Know where your code will break, without handing it over.
Kestrel reads your GitHub repositories read-only, analyzes a temporary copy, deletes it, and gives you a receipt. Every month you get a report your team can act on and your investors can read.
- Read-only GitHub app
- Code copy deleted after every run
- Never used to train AI
- Repository
- acme/payments-api
- Code version
- 8c41e02 · 31 Aug 2026
- Copy created
- 09:14:02 UTC
- Analysis finished
- 09:16:40 UTC
- Copy deleted
- 09:16:41 UTC
- Code kept
- None
How it works
Three steps. Your first report, with 12 months of history, is ready in minutes.
- 01
Connect read-only
Install the Kestrel GitHub app on the repositories you choose. It can read code and nothing else: no writing, no issues, no secrets.
- 02
We analyze, then delete
Each run copies the code into its own isolated workspace, measures it, and deletes the copy. You get a receipt every time.
- 03
Get two reports
A team view with what to fix first and who owns it, and an executive view you can share with investors, with names removed.
Eight signs of health, every month
Measured on the code exactly as it was on the last day of each month, and compared with the month before.
We never store your code. Here is exactly what we touch.
GitHub permissions we ask for
| Contents | Read-only |
| Metadata | Read-only |
| Write access, issues, pull requests, secrets, actions | Never |
You pick the repositories. Remove one, or uninstall the app, at any time from GitHub or from Kestrel.
What we keep
- Measurements and scores
- File and folder names
- Contributor names, never shown to investors
- Receipts
What we never keep
- Your source code
- Secrets or credentials
- GitHub access tokens
- Anything for AI training
- An isolated workspace per runEach analysis runs in its own process and private folder, which is destroyed when it ends.
- Short-lived, read-only accessEvery run gets a fresh one-hour token for a single repository. We never store it.
- Receipts you can fileEvery run and every deletion produces a receipt with times and versions.
- SOC 2 in progressWe are working toward SOC 2. Ask us for our current security documentation.
One page your investors can read
Share an executive view by email. The link expires, you can revoke it, and you see when it was opened. Developer names are always hidden.
Your team gets the detailed view: what to fix first, who owns it, and whether it got better since last month.
- Payments code depends on one developer.
- Most recent work went to fixes, not new features.
- Test coverage fell from 62% to 55% in three months.
Start with your most important repository.
We review every request and reply within one business day.