LWBRUT is architected from the ground up for strict security posture. Code payloads parsed during PR reviews are maintained strictly in-memory (RAM) in containerized sandbox workers. Upon completion of AST validation and webhook dispatch, worker memory buffers are wiped.
Model reasoning is handled through Anthropic's direct commercial Claude 3.5 Sonnet API endpoints:
To eliminate security risks stemming from model hallucination, generated patches are passed through Tree-sitter AST validation before any comment or review is recorded on GitHub. Patches that violate syntactic safety or introduce unverified dependencies are discarded.
For organizations requiring air-gapped or dedicated sovereign clouds, LWBRUT provides Model Context Protocol (MCP) servers and containerized deployments within your AWS VPC, GCP, or Azure subscription.
We welcome responsible disclosure. Reports may be submitted to security@lwbrut.com.