Security & trust
What happens when you connect GitHub, exactly.
Olmene finds the problem and prepares the fix. Your team decides what gets merged.
Last updated: October 2026
The workflow
- 01OlmeneAnalyzeReads your public website
- 02OlmeneIdentifyDeterministic checks and a cited report
- 03OlmeneGenerate the fixConcrete edits, each with its evidence
- 04OlmeneOpen a pull requestOn a new branch in your repository
- 05Your teamYou reviewLine by line, like a teammate's work
- 06Your teamYou mergeYour own pipeline deploys, as usual
- 07OlmeneOlmene verifiesRe-checks your live site
GitHub permissions
Olmene connects through a GitHub App. GitHub shows you these exact permissions before you install it.
| Permission | Access | Why Olmene needs it |
|---|---|---|
| Contents | Read and write | To read the files a fix touches (the file list and your homepage or layout files) and to commit the fix to a new branch. |
| Pull requests | Read and write | To open the pull request and to see whether you merged or closed it. |
| Metadata | Read | Required by GitHub for every app: repository names and basic information. |
Nothing else: no access to issues, Actions, workflows, secrets, settings, administration or your organization, and no webhooks.
What the app can and cannot do
- YesRead source code in the repositories you selectOnly the files a fix needs: the file list and your homepage or layout files.
- YesCreate branchesOnly new branches named olmene/fix-…. It never moves or rewrites an existing branch.
- YesCreate pull requestsOne per fix run, with an explanation, the evidence and undo steps for every change.
- NoMerge pull requestsOlmene's GitHub client cannot call GitHub's merge endpoint. You merge.
- NoPush to your main branchEvery write goes to Olmene's own branch. A write to your default branch is refused before it is sent.
- NoDelete branches or repositories, or force-pushDelete and force-push requests are blocked in code, and the app has no administration permission.
- NoAccess repositories you did not selectEach fix run is locked to one repository, and every request is checked against it.
- NoDeploy or change your production siteChanges reach production only when you merge and your own pipeline deploys.
You choose the repositories
When you install the app, GitHub lets you choose Only select repositories. Olmene can only see the repositories you pick, and each fix run works on the one you choose. You can change the selection or uninstall the app at any time in GitHub → Settings → Applications. Disconnecting in Olmene deletes the connection and checks that access has ended.
Production stays in your hands
Olmene never deploys and never merges. A fix reaches your live site only after your team reviews the pull request, merges it, and your existing deployment pipeline ships it. After that, Olmene reads your public website to confirm the fix is live; it needs no extra access for this.
Credentials
GitHub access tokens are created for each run, expire after one hour and are kept in memory only, never stored. The GitHub sign-in used when you connect is used once to confirm the installation belongs to you, then discarded. The app's own private key is stored encrypted (AES-256-GCM) with a key kept outside the database.
Safeguards
Every action is written to an audit log and to a receipt you can keep. Anything Olmene is not confident about is skipped, with the reason. An operator switch stops all repository writes at once; it is checked before every write.
Data handling
| Data | What happens to it | Kept for |
|---|---|---|
| Your email and account | Used for sign-in (Google or an emailed link) and your plan. | Until you delete your account |
| Website URL, the context you add, your reports | Used to run your analyses. Reports stay in your account. | Until you delete your account |
| Repository code | Read during a fix run, not stored. Olmene keeps only the proposed changes (the changed lines with three lines of context), the explanations, and SHA-256 fingerprints of each edited file before and after. | With your fix runs, until you delete your account |
| Free-scan IP address | Used only to rate-limit free scans. | 24 hours |
| Payment details | Handled by Polar, the merchant of record. Olmene never sees card numbers. | Per Polar's policy |
AI processing
Reports and fix copy are written by Gemini models on Google Cloud Vertex AI, which does not train on customer data. The models receive public website content and research results. For a fix, they receive product facts from your report and the current page title, headline and image file names, not your repository files. Olmene does not use your data to train models either.
Deletion
Ask us to delete your account and we delete your reports, fix runs and account data within 30 days, except where the law requires us to keep something. You can uninstall the GitHub app at any time without asking us.
Processors
Cloudflare (hosting) · Supabase (database, sign-in, background jobs) · Google Cloud Vertex AI (AI models) · Tavily (live web research) · Brevo (sign-in emails) · Polar (payments) · GitHub (only when you connect a repository) · Google Analytics (only if you accept cookies).
Who operates Olmene
Olmene is built and operated by Bytesphere_Dynamics, an independent software studio. Bytesphere_Dynamics is a trading name, not a registered company.
To report a security issue or ask a question, email byteshpere.dynamics@gmail.com