Local by default
Runrail Desktop binds only to 127.0.0.1. Repository content and generated review artifacts stay on the operator's machine.
Security boundary
The local product constrains what can be inspected, executed, persisted, and applied. AI output does not gain direct shell, patch, answer, or repository authority, and every unsupported condition fails closed.
Runrail Desktop binds only to 127.0.0.1. Repository content and generated review artifacts stay on the operator's machine.
An optional .runrail/review-contract.json is read from the selected base commit. Candidate changes cannot weaken its budgets or required evidence.
Runrail uses fixed Python, JavaScript, JSON, TypeScript, TSX, and JSX syntax or parse checks. Unsupported changed source types block the preflight; package scripts, project code, and arbitrary shell instructions are never run.
The product exports a patch for review and does not apply it automatically.
The path-free passport binds checks, contract fingerprint, relation, and review outcome to the audit checksum. It does not authenticate who created the evidence.
Review Coverage carries attention only for an exact unique hunk in a related revision. Changed, shifted, split, duplicated, ambiguous, and new hunks reset to unreviewed; attention never becomes approval.
The free browser workspace compares related audit files without opening either repository or sending files to Veyact. Licensed CLI comparison is available in Pro.
Offline deterministic recommendations require no model. Optional DeepSeek advice receives no source or diff and may return only fixed candidate IDs or ABSTAIN, with authority none.
Security reports are accepted at the published support address. The current Runrail 2.x security-support period runs through 28 July 2031, with fixes delivered through the current supported release channel.
Security detail