Bound the execution
Choose the connected machine, allowed root, repositories, branch, files, model, and tools that belong to a Mission.
GRAIN SECURITY
Grain keeps execution scope, code changes, test and run evidence, model routing, and human decisions attached to the Mission—from brief to approved result.
BOUNDARY
IDENTITY
EXECUTION
EVIDENCE
REVIEW
APPROVAL
REVIEWABLE BY OPERATING DESIGN
Security starts with a narrow execution boundary and an inspectable result. Grain keeps the route, work, evidence, and decision points visible instead of collapsing them into a single AI answer.
Choose the connected machine, allowed root, repositories, branch, files, model, and tools that belong to a Mission.
Changed files, diff statistics, run status, artifacts, and review comments remain attached to the task for inspection and follow-up.
Organization policy can stop a Mission for human approval before Git push, publish, deploy, or another sensitive action.
CODE REVIEW WITHOUT THE THEATER
Grain does not turn a green check into a blanket security claim. Routine code work stays inspectable; when a change needs a dedicated security-focused pass, request one as its own priced, traceable task.
Local runs work in isolated task directories. Cloud work returns a diff when policy or credentials do not permit a push, so unapproved changes remain visible without moving upstream.
A requested review is a separate Mission with clear $15 / 1,500-credit pricing, duplicate-purchase protection, guarded dispatch, and a failed-run refund path.
Before recent project messages or saved code are sent to a hosted provider, Grain names the destination and asks. Images require their own consent, and changed context triggers review again.
THE REVIEW PATH
Grain makes code changes reviewable and supports a dedicated security-review workflow. It does not claim that every output is independently audited, vulnerability-free, or covered by an unstated certification.
Name the outcome and constrain the machine, project, branch, context, model, tools, and spend available to the run.
Inspect the diff, files, test results, run status, questions, artifacts, and focused review findings in one task record.
A person can accept the result, return comments for another run, or keep the change from pushing or publishing.
READY WHEN YOU ARE
Tell us where work may run, what it may access, how changes must be reviewed, and which decisions must remain human.
Talk to Grain