Physically can't change anything
Maulwurf authenticates with read-only scopes. It cannot push, merge, open PRs, or modify a single line. The worst it can do is answer a question.
Never trains models
Your code is indexed to answer your questions — nothing else. It is never used to train or fine-tune models. Not negotiable, not a toggle.
Encrypted everywhere
Code and indexes are encrypted in transit and at rest, by design. There is no plaintext copy sitting on a disk somewhere.
Your index, your walls
Each customer's index is isolated. Your codebase never informs another team's answers — not as context, not as training signal, not at all.
Purge on demand
Disconnect and purge your entire index at any time, no questions asked. Deletion is deletion — not archival, not "deactivation".
Only what you point at
Maulwurf indexes only the repositories you connect. It doesn't wander your org, your issues, or your CI logs unless you ask it to.
Questions about our security?
Ask us anything. We'll answer with the same directness as this page.
Contact us