Trust

Keep code access scoped and make every run auditable.

DexCode is built for teams that need AI coding work to leave a clear, reviewable record.

Boundary

What DexCode holds

DexCode stores run metadata and evidence. It does not need unlimited repository access.

Scoped tokens

Required

CLI and API tokens should be revocable, named and scoped to the account.

Evidence retention

Required

Artifacts need configurable retention because traces and screenshots can contain sensitive context.

Human approval

Required

Merge, deploy and customer-facing changes still need explicit owner approval.

Controls

Governance surface

Budgets, provider credentials, access controls and audit logs stay visible to the organization.

Budgets

Control

Set weekly and monthly limits by account, user and provider.

Audit export

Control

Export run history, actors, tokens, PRs and evidence for review.

Private artifacts

Control

Separate public PR links from private account-only evidence.

Shared app

Trust starts with clear access and readable receipts.

Every run should make ownership, credentials, cost, evidence and approval state easy to inspect.

Open dashboard