Skip to content

Trust and data

What Kanjin sends, keeps and never does.

Classification is a judgement made by a model on a block of code and the context around it. It can be wrong, and it can be missing. This page states what that judgement needs from your code, and what happens to it.

The source that is sent

To classify a changed block, Kanjin sends the enclosing function in both the old and the new version, the imports it uses, and the type and constant declarations it references. That is wider than the changed lines. Before anything private is submitted, you see the file list and its size, and you can decline.

The classifier

The source reaches an external service, the classifier, for analysis. It answers two questions for each block: what kind of change it is, and whether it preserves behavior. Kanjin stores the answer; the classifier writes no code.

What Kanjin keeps, and for how long

While an analysis runs, Kanjin holds its input — the changed files, both versions — so the job survives a restart. It deletes that input when the analysis completes or is canceled, and one hour after a failed or partial analysis, so a retry works.

After that, Kanjin keeps no source code on its server, with one exception: the source of a block whose classification a reviewer corrects, because a second request must quote it. It keeps the judgments: block ranges, categories, probabilities and the versions that produced them. Everything Kanjin keeps is deleted after one year.

Storage location: to be confirmed.

Signing in is not repository access

Your login identifies you. It does not let Kanjin read a repository. An administrator connects a provider to the workspace, and each member links their own provider account. Kanjin shows each member only what that account can read at the provider; it mirrors the provider and never grants access.

Collapsed does not mean cleared

A collapsed block is one the classifier classified as behavior-preserving. That is a classification, not a proof. Kanjin never labels a change safe to merge, and has no approval action.

Nothing disappears on failure

If analysis fails, times out, or comes back partial, the affected code stays fully visible and the review says so. Missing classification removes collapsing, never code.

Back to the homepage