Security & data flow

Know where your code goes during a review.

Ironwood runs in your environment. Your repository, credentials, review data and configured engineering knowledge stay under your organisation's operational control.

Review traffic and licence traffic are separate.

Source code and review prompts are sent only through the review path you configure. The Ironwood-hosted licence service is used for evaluation and licence validation and does not receive review content.

Review data flow

RepositoryYour source-control provider
IronwoodRuns in your environment
AI providerYour configured account or local model

Ironwood retrieves the code and context needed for the review, processes it in your deployment and sends the review request to the AI provider or local model your team configured.

What stays in your environment

  • Ironwood application and database
  • Repository credentials
  • AI-provider credentials
  • Engineering knowledge and indexed context
  • Review history and findings
  • Operational and diagnostic information

What can leave your environment

When you use a hosted AI provider, the review prompt and selected code or context are sent to that provider under the account and terms your organisation configured. If you use a local model such as Ollama, that AI request can remain inside your own infrastructure.

Licence validation

Ironwood contacts the Ironwood-hosted licence service to validate an evaluation or paid licence. That service handles licence state and installation identity. It is not part of the code-review path.

Credentials

Your team manages the credentials used for source control and AI providers. Ironwood Solutions does not receive those credentials through the public website purchase or evaluation flow.

Support

When support needs operational details, Ironwood can generate a sanitised support bundle. Review the bundle before sharing it. The support workflow is designed not to automatically upload your source code or provider credentials.