Local execution
Your controller process, repository checkout, dependencies, and secrets stay in customer-controlled CI.
The Smethe Cloud security model starts from one constraint: customer controller code executes in the customer’s own environment.
Product-preview security model · July 22, 2026
Your controller process, repository checkout, dependencies, and secrets stay in customer-controlled CI.
The hosted boundary accepts versioned result manifests, not arbitrary source bundles or executable controller code.
Paid private evidence is planned for 90-day expiry with immediate deletion support.
smethe.evidence/v1 bundle.Controller source, repository checkout, secret values, and arbitrary executable artifacts are outside the intended upload contract.
The planned GitHub App will request the minimum repository permissions needed to identify commits, receive relevant webhook events, and write check results. Webhook signatures, installation ownership, replay protection, and idempotency are release requirements. The final permission list will be shown before installation.
Repository access does not authorize billing. Authenticated checkout and billing-portal actions require verified organization-owner access and a same-session CSRF token; checkout is offered only after written pilot scope is accepted.
Before general availability, the hosted service is intended to include secure cookie sessions, CSRF protection, strict input validation, rate limiting, dependency and container scanning, secrets in a managed secret store, immutable deployments, staging, monitored health checks, backup and restore testing, and a documented rollback path.
Neither the core engine nor Cloud evidence proves that a controller is safe, compliant, certified, or free from defects. Security controls also do not make functional simulation an appropriate substitute for physics-based simulation, HIL, threat analysis, safety engineering, or real-world validation.
If you believe you found a vulnerability in this website or a Smethe build you were authorized to access, email support@talkdoc.com with the subject [SECURITY] Smethe report.
We will acknowledge a credible report as soon as practical and coordinate a secure channel if sensitive details are needed. Smethe does not currently operate a public bug-bounty program, and this page does not promise payment or create authorization beyond the scope above.
Design partners can request a focused architecture and data-flow review during pilot scoping. General questions can be sent through the contact form.