Pich logoPichdocs
Docs menu: Execution boundaries

Security

Execution boundaries

What Pich reads, what it never runs, and where the proof runs.

Boundary

Pich never installs, builds, or runs code from a repository you give it. It reads a fixed list of files as text.

The runtime proof builds and runs only two bundled fixtures, locally, not on the hosted site.

  • The browser never talks to SERV or GitHub directly; all calls go through the server routes.
  • /api/explain recomputes the verdict on the server instead of trusting a verdict sent by the browser.
  • Advisory text is capped at 12,000 characters, and every route is rate limited.

Edit this page on GitHub