# Code review, security, and governance at Grain

> How Grain keeps AI code work scoped and reviewable, gates consequential actions, requests provider-specific consent, and offers a dedicated security-review task when needed.

- Canonical page: [/security](https://grain.sh/security)
- Agent-readable page: [/agents/security.md](https://grain.sh/agents/security.md)
- Section: Company

## What this page covers

- Execution boundaries across connected machines, allowed roots, repositories, branches, files, models, tools, and spend
- Reviewable changed files, diffs, run status, artifacts, test evidence, and line-level review comments
- Organization policy that can require human approval before Git push, publish, deploy, or another sensitive action
- On-demand security review with explicit $15 / 1,500-credit pricing, duplicate-purchase protection, guarded dispatch, and a failed-run refund path
- Destination-specific consent for hosted project context and separate consent for images
- A precise distinction between reviewable code, a requested security review, and an independent audit or certification

## About Grain

Grain is a multi-agent work platform. A person describes an outcome as a Mission, Grain coordinates the models, tools, files, repositories, and connected computers needed to do the work, and the result returns for review.

Start with [the complete agent-readable index](https://grain.sh/agents/index.md) or read [the full site corpus](https://grain.sh/llms-full.txt).
