Connected repositories
0Cyberscan workspace
Find the path that breaks.
Run each repository review in isolation. Keep the commit, findings, decisions, and report tied to the same run.
Completed runs
0Open findings
0Estimated scan cost
N/ARun economics
Cost by day
Latest activity
Recent runs
Source access
Repositories
Authorize only the codebases you want the private harness to inspect.
GitHub App access
Connected accounts
Change the selected repositories on GitHub, then return here to sync.
Repository filters
0 repositoriesNo repository access
Choose the code you want reviewed.
Your GitHub sign-in confirms who you are. Repository access is a separate, one-time choice.
Choose one or more repositories in GitHub and return here. You can add or remove repositories later without losing past scan evidence.
Versioned evidence
Scan runs
Track every run from submission through verification.
Security investigations
Findings
Confirm the evidence, validate the behavior safely, and record what happens next.
Workspace boundaries
Account & trust
See who can access source, where each scan runs, which model reviews it, and what Prem keeps.
01 · Identity boundary
Not signed in
GitHub signs you in. Repository access is granted separately through the GitHub App.
Manage repository access02 · Source permission
Selected repositories only
- The GitHub App can read only the repositories you select.
- Each worker receives a short-lived installation token scoped to one repository.
- Removing a repository blocks new scans; prior reports stay in your workspace.
03 · Execution boundary
One isolated job per scan
- Each scan gets a temporary worker and a clean checkout of the requested commit.
- Prem reviews the code inside that job. Scans never share a checkout.
- The worker reaches GitHub for source, Prem Router for model calls, and Prem to return run status and findings.
04 · Analysis routing
Mode-based models
- Your scan mode selects the model before the job starts.
- The workspace keeps run metadata, usage, findings, decisions, and reports.
- The source checkout is not stored in the workspace record.