Local by default
Runrail Desktop binds only to 127.0.0.1. Repository content and generated review artifacts stay on the operator's machine.
Security boundary
The local product constrains what can be inspected, executed, persisted, and applied. AI output does not gain direct shell, patch, answer, or repository authority, and every unsupported condition fails closed.
Runrail Desktop binds only to 127.0.0.1. Repository content and generated review artifacts stay on the operator's machine.
Runrail accepts supported workflows and verifier commands, not arbitrary shell instructions.
The product exports a patch for review and does not apply it automatically.
Patch, audit, review, rollback, and policy evidence remain attached to the review.
The free browser workspace compares related audit files without opening either repository or sending files to Veyact. Licensed CLI comparison is available in Pro and above.
Offline deterministic recommendations require no model. Optional DeepSeek advice receives no source or diff and may return only fixed candidate IDs or ABSTAIN, with authority none.
Security detail