Monthly code checkup

Know where your code will break, without handing it over.

Kestrel reads your GitHub repositories read-only, analyzes a temporary copy, deletes it, and gives you a receipt. Every month you get a report your team can act on and your investors can read.

  • Read-only GitHub app
  • Code copy deleted after every run
  • Never used to train AI
Deletion receiptKR-2026-0901-4F7A
Repository
acme/payments-api
Code version
8c41e02 · 31 Aug 2026
Copy created
09:14:02 UTC
Analysis finished
09:16:40 UTC
Copy deleted
09:16:41 UTC
Code kept
None
Example. One receipt for every run, ready for your security team.

How it works

Three steps. Your first report, with 12 months of history, is ready in minutes.

  1. 01

    Connect read-only

    Install the Kestrel GitHub app on the repositories you choose. It can read code and nothing else: no writing, no issues, no secrets.

  2. 02

    We analyze, then delete

    Each run copies the code into its own isolated workspace, measures it, and deletes the copy. You get a receipt every time.

  3. 03

    Get two reports

    A team view with what to fix first and who owns it, and an executive view you can share with investors, with names removed.

Eight signs of health, every month

Measured on the code exactly as it was on the last day of each month, and compared with the month before.

Shared knowledgeKnowledge islandsHow much of each part depends on one person.
Shared knowledgeKnowledge balanceHow evenly work is shared between people.
Engineering workFeature effortHow much work builds new things rather than fixing.
App structureFragilityHow far a bug fix has to spread.
Code healthComplexityHow easy the code is to follow.
Code healthDuplicationHow much code is copy-pasted.
Code healthTest coverageHow much code automated tests exercise.
Code healthDocumentationHow much shared code is explained.
Security

We never store your code. Here is exactly what we touch.

GitHub permissions we ask for

ContentsRead-only
MetadataRead-only
Write access, issues, pull requests, secrets, actionsNever

You pick the repositories. Remove one, or uninstall the app, at any time from GitHub or from Kestrel.

What we keep

  • Measurements and scores
  • File and folder names
  • Contributor names, never shown to investors
  • Receipts

What we never keep

  • Your source code
  • Secrets or credentials
  • GitHub access tokens
  • Anything for AI training
  • An isolated workspace per runEach analysis runs in its own process and private folder, which is destroyed when it ends.
  • Short-lived, read-only accessEvery run gets a fresh one-hour token for a single repository. We never store it.
  • Receipts you can fileEvery run and every deletion produces a receipt with times and versions.
  • SOC 2 in progressWe are working toward SOC 2. Ask us for our current security documentation.

One page your investors can read

Share an executive view by email. The link expires, you can revoke it, and you see when it was opened. Developer names are always hidden.

Your team gets the detailed view: what to fix first, who owns it, and whether it got better since last month.

Acme Logistics · August 2026Sample data
KnowledgeWatch
WorkNeeds action
StructureHealthy
Code healthWatch
  1. Payments code depends on one developer.
  2. Most recent work went to fixes, not new features.
  3. Test coverage fell from 62% to 55% in three months.
Example with made-up data.

Start with your most important repository.

We review every request and reply within one business day.

Request access