SECURITY

Your code.Your environment.Your control.

Ironwood runs on infrastructure your organisation controls. You choose the repositories it can access, the AI providers it uses and how credentials are managed.

YOUR ENVIRONMENT
Repository accessIronwoodReview data
Configured by your teamYour AI provider
Customer controlledDeploymentRepository accessAI credentialsReview data
THE SECURITY MODEL

Ironwood does not need to host your source code.

Your organisation runs Ironwood and controls the connections around it. Ironwood Solutions does not need to receive or store your source code, review prompts or findings to run a review.

Runs in your environment

Ironwood is deployed on infrastructure your organisation controls. Ironwood Solutions does not host the code-review platform for you.

You control repository access

Your team configures the GitHub, Azure DevOps or Bitbucket connection and decides which repositories Ironwood can access.

You choose the AI providers

Use your organisation's OpenAI, Claude or Gemini account, or run supported models locally with Ollama.

Review data stays with your installation

Review history, findings and platform records are stored by the Ironwood installation you operate.

REVIEW DATA FLOW

Know where review data goes.

If you use a hosted AI provider, the review input needed for analysis goes directly from your Ironwood installation to that provider under your organisation's account. It does not need to pass through an Ironwood Solutions-hosted review service.

01RepositoryYour configured source-control provider
02IronwoodRuns in your environment
03AI providerChosen and configured by your team
04FindingsReturned to your Ironwood installation
If you use Ollama locally

The model can run inside your own environment instead. This gives teams a path to keep supported review and AI workloads within infrastructure they control.

ACCESS AND CREDENTIALS

Your team controls the connections.

Ironwood uses the source-control and AI provider configuration supplied by your organisation. The product does not require Ironwood Solutions to hold those credentials for you.

Credentials

Source-control and AI provider credentials are supplied through your installation configuration. Your organisation manages them using its own environment and secret-management process.

Application access

Ironwood includes local authentication with Admin, Reviewer and Viewer roles. Administrative and operational permissions are enforced by the application API.

Local AI option

Teams that do not want review input sent to a hosted AI provider can use supported local models through Ollama.

Licence validation

Licence and evaluation validation use the Ironwood-hosted licence service. This is separate from the code-review path.

FOR SECURITY REVIEWERS

Need the technical detail?

The documentation covers review data flow, what stays inside the installation, what can leave it, credentials, roles, licence validation and support information.

EVALUATE IN YOUR ENVIRONMENT

Run Ironwood with your own repositories and AI providers.

30 days · 2 developers · Full Professional features · No credit card.

Start free evaluation