The model works through typed tools
The reviewer reads files, searches code, and queries environment evidence through typed tools. None of them makes an HTTP request or runs SQL.
Proofline fixes the repository, commit, and environment snapshot before the model starts. Tool inputs name only paths, filters, and identifiers, and Proofline checks authorization outside the model.
Repository text is data
Proofline marks repository and pull request text as untrusted before the model sees it. Guideline files such as AGENTS.md are read at the merge base, so a pull request cannot rewrite its own review instructions.
Proofline classifies a pull request comment into a fixed set of commands, and only after it confirms the author has write access. The comment text never becomes an instruction.
Before each model call, Proofline runs versioned credential masking over the request. If masking is unavailable, the call does not proceed.
Short-lived cloud credentials
Proofline requests GitHub installation tokens and AWS role sessions when it needs them and stores neither. Google Cloud access uses workload identity federation, with no stored key.
A Vercel connection uses an API token scoped to the project or team. A Cloudflare connection uses a token limited to the read permissions the form lists. Proofline encrypts both at rest.
Proofline encrypts model provider keys with AES-256-GCM and never shows them again.
Experiments run in a disposable VM
To test a premise, the reviewer can run code in a sandbox VM. The VM has no cloud identity and no external address. Its outbound traffic passes a proxy that allows only Proofline, GitHub, and package and container registries.
It never holds a model provider key, a cloud credential, or a write credential. Its only repository access is a read-only token for the repository under review. Proofline deletes the VM when its job ends, or shortly after its time limit at the latest.
Questions
Can prompt injection in a pull request widen what the AI reviewer can access?
No. Proofline fixes the repository, commit, environment, and tool permissions outside the model, and checks each tool call against them. The model cannot widen its own scope.
Can the AI reviewer push code or merge a pull request?
No. Proofline's reviewer model has no write credential. Merge gates follow a fixed policy you configure, and the model does not decide a merge.
Does Proofline send my code to a model provider?
Yes. The code and evidence in each model request go to the model provider. With your own key, they go to your provider account. Enterprise customers can also run Proofline on premises or in their own cloud. See security and data access.