Skip to content
olmene

Security & trust

What happens when you connect GitHub, exactly.

Olmene finds the problem and prepares the fix. Your team decides what gets merged.

Last updated: October 2026

The workflow

  1. 01OlmeneAnalyzeReads your public website
  2. 02OlmeneIdentifyDeterministic checks and a cited report
  3. 03OlmeneGenerate the fixConcrete edits, each with its evidence
  4. 04OlmeneOpen a pull requestOn a new branch in your repository
  5. 05Your teamYou reviewLine by line, like a teammate's work
  6. 06Your teamYou mergeYour own pipeline deploys, as usual
  7. 07OlmeneOlmene verifiesRe-checks your live site

GitHub permissions

Olmene connects through a GitHub App. GitHub shows you these exact permissions before you install it.

PermissionAccessWhy Olmene needs it
ContentsRead and writeTo read the files a fix touches (the file list and your homepage or layout files) and to commit the fix to a new branch.
Pull requestsRead and writeTo open the pull request and to see whether you merged or closed it.
MetadataReadRequired by GitHub for every app: repository names and basic information.

Nothing else: no access to issues, Actions, workflows, secrets, settings, administration or your organization, and no webhooks.

What the app can and cannot do

  • YesRead source code in the repositories you selectOnly the files a fix needs: the file list and your homepage or layout files.
  • YesCreate branchesOnly new branches named olmene/fix-…. It never moves or rewrites an existing branch.
  • YesCreate pull requestsOne per fix run, with an explanation, the evidence and undo steps for every change.
  • NoMerge pull requestsOlmene's GitHub client cannot call GitHub's merge endpoint. You merge.
  • NoPush to your main branchEvery write goes to Olmene's own branch. A write to your default branch is refused before it is sent.
  • NoDelete branches or repositories, or force-pushDelete and force-push requests are blocked in code, and the app has no administration permission.
  • NoAccess repositories you did not selectEach fix run is locked to one repository, and every request is checked against it.
  • NoDeploy or change your production siteChanges reach production only when you merge and your own pipeline deploys.

You choose the repositories

When you install the app, GitHub lets you choose Only select repositories. Olmene can only see the repositories you pick, and each fix run works on the one you choose. You can change the selection or uninstall the app at any time in GitHub → Settings → Applications. Disconnecting in Olmene deletes the connection and checks that access has ended.

Production stays in your hands

Olmene never deploys and never merges. A fix reaches your live site only after your team reviews the pull request, merges it, and your existing deployment pipeline ships it. After that, Olmene reads your public website to confirm the fix is live; it needs no extra access for this.

Credentials

GitHub access tokens are created for each run, expire after one hour and are kept in memory only, never stored. The GitHub sign-in used when you connect is used once to confirm the installation belongs to you, then discarded. The app's own private key is stored encrypted (AES-256-GCM) with a key kept outside the database.

Safeguards

Every action is written to an audit log and to a receipt you can keep. Anything Olmene is not confident about is skipped, with the reason. An operator switch stops all repository writes at once; it is checked before every write.

Data handling

DataWhat happens to itKept for
Your email and accountUsed for sign-in (Google or an emailed link) and your plan.Until you delete your account
Website URL, the context you add, your reportsUsed to run your analyses. Reports stay in your account.Until you delete your account
Repository codeRead during a fix run, not stored. Olmene keeps only the proposed changes (the changed lines with three lines of context), the explanations, and SHA-256 fingerprints of each edited file before and after.With your fix runs, until you delete your account
Free-scan IP addressUsed only to rate-limit free scans.24 hours
Payment detailsHandled by Polar, the merchant of record. Olmene never sees card numbers.Per Polar's policy

AI processing

Reports and fix copy are written by Gemini models on Google Cloud Vertex AI, which does not train on customer data. The models receive public website content and research results. For a fix, they receive product facts from your report and the current page title, headline and image file names, not your repository files. Olmene does not use your data to train models either.

Deletion

Ask us to delete your account and we delete your reports, fix runs and account data within 30 days, except where the law requires us to keep something. You can uninstall the GitHub app at any time without asking us.

Processors

Cloudflare (hosting) · Supabase (database, sign-in, background jobs) · Google Cloud Vertex AI (AI models) · Tavily (live web research) · Brevo (sign-in emails) · Polar (payments) · GitHub (only when you connect a repository) · Google Analytics (only if you accept cookies).

The full details are in the Privacy Policy.

Who operates Olmene

Olmene is built and operated by Bytesphere_Dynamics, an independent software studio. Bytesphere_Dynamics is a trading name, not a registered company.

The founder on LinkedIn →

To report a security issue or ask a question, email byteshpere.dynamics@gmail.com