Security & privacy

We never train models on your code.

Pacecar reviews proprietary diffs. Enterprise buyers should know exactly where that code goes, whether anyone trains on it, and whether inference uses zero-data-retention endpoints.

Short version: inference providers get zero data retention. We never train models on your proprietary code. We do store review records so we can evaluate and improve review quality.

Direct answers

What engineering leaders ask first

Do you train models on our codebase?

No. Pacecar does not use your proprietary code to train, fine-tune, or otherwise improve foundation models — ours or a provider’s. Improving review quality means evaluating stored reviews, tuning prompts and checklists, and (when we train anything) using public or otherwise permitted data — not private customer repos.

Do you use zero-data-retention APIs?

Yes for inference providers. Requests go through OpenRouter with Zero Data Retention (ZDR) enforced, so model providers do not retain prompts. OpenRouter itself does not retain prompts unless prompt logging is opted in — we do not opt in. That is separate from what Pacecar stores on our side after the review runs.

Do you store our reviews?

Yes. We store review artifacts (findings, related PR metadata, and the diff context needed to judge the review) so we can measure precision/recall, debug bad comments, and make the product better over time. That storage is for product quality — not for training models on your codebase.

Where does the code go?

GitHub notifies Pacecar on PR open/update. We fetch the diff via the GitHub App, send it plus our checklist to a ZDR model endpoint, post the sticky review comment, and retain the review record for quality evaluation and operations (billing, comment updates). Providers on the inference path do not keep the prompt.

Data path

How a review moves data

No paste into a consumer chatbot. Diffs stay inside the App → ZDR inference → PR comment path.

  1. 01

    GitHub webhook

    Your org’s GitHub App install notifies Pacecar on PR open and push.

  2. 02

    Diff over GitHub API

    Pacecar reads the pull request diff with the permissions you granted at install.

  3. 03

    ZDR inference

    The diff and checklist go to a model endpoint that does not retain or train on the prompt.

  4. 04

    Comment + quality store

    Findings post back to the PR. We keep the review record so we can evaluate and improve review quality — without training on your code.

What we keep

Store for quality. Never train on your IP.

We do store

  • GitHub App install and account linkage
  • Billing and usage events for reviews that ran
  • Review artifacts — findings, PR metadata, and diff context needed to evaluate and improve review quality

We do not

  • Train or fine-tune foundation models on your proprietary codebase
  • Let inference providers retain or train on prompts (ZDR enforced)
  • Sell your code or use it outside running and improving the review product

Uninstall the GitHub App anytime to stop reviews and revoke Pacecar’s access to your organization.

Review every PR without surrendering the codebase.

Install Pacecar on your GitHub organization. Same checklist on every open and update — without training on your code.

Install on GitHub

Free to install. You only pay when reviews run.