> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pre.dev/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Agents: start with https://docs.pre.dev/agents.md, which has complete recipes, plan access, polling rules, errors and limits.
> Authenticate with the workspace API key (pdk_…) from Integrations → Built-in, sent as Authorization: Bearer <key>.
> REST API: https://api.pre.dev (OpenAPI: https://docs.pre.dev/api-reference/openapi.json). AI Gateway: https://api.pre.dev/v1, OpenAI-compatible (OpenAPI: https://docs.pre.dev/api-reference/ai-gateway.openapi.json).
> pre.dev MCP server: https://api.pre.dev/mcp. Search these docs over MCP at https://docs.pre.dev/mcp.

# Trust and data handling

> How pre.dev checks that code is private, what is removed before anything is delivered, and how licensing works.

## Contamination

### Exposure check

Before a repository is analyzed, listed, or used for RL tasks, it goes through an exposure check. It is refused if:

* its host reports it as public, or its page loads for a signed-out visitor;
* the Internet Archive holds a public capture of it;
* it is a fork of a project from outside the team that licensed it;
* it is published on npm or PyPI, with the registry entry pointing back at it;
* pre.dev's own agent created it.

Weaker signals, such as an open-source license file or stars and forks on a private repository, go to a person for review. A refused repository is never listed, delivered, or used for tasks.

Codebases are checked again before each delivery, and a repository found public, archived, forked, or published is held back. See [delivery and re-delivery](/labs/codebases#delivery-and-re-delivery).

### What an RL solver sees

The solver's workspace holds the repository at the before-state with no git history. The original commit message is withheld, and the task container runs without network access. See [RL Tasks](/labs/rl-tasks).

### Checking overlap yourself

Every RL task bundle lists the SHA-256 of each file in its starting repository, plus a root hash over the whole tree, so you can check overlap against your own corpus. See [checking overlap](/labs/rl-tasks#checking-overlap-with-your-corpus).

## Data handling

* **Cleaned before anything reads it.** Secrets and personal data are removed from the full git history before the code is counted, graded, delivered, or turned into tasks. Contributors become pseudonyms. See [how the history is cleaned](/labs/codebases#how-the-history-is-cleaned).
* **Checked again at export.** When an RL task is exported, its files are scanned for private-key blocks, AWS access key IDs, and bearer tokens in `Authorization` headers. Before the final bundle ships, its task files and QA evidence are also scanned for MongoDB, Redis, PostgreSQL, MySQL, and AMQP connection URLs that carry credentials. Any hit stops the export. A codebase zip is built only if it passes the [delivery checks](/labs/codebases#delivery-checks).
* **No names.** Codebases are delivered under catalog IDs, and the zip, its folder, and its README carry no owner or repository name. RL tasks carry opaque task IDs.
* **Verifiable transfer.** RL tasks ship as `.tar.gz` archives with SHA-256 checksums. Codebases ship through signed download links that expire after seven days.

## Licensing

* Every codebase is licensed directly from the team that built it, under a signed agreement that lets pre.dev sublicense it to labs.
* A repository is delivered only while its owner's signed agreement is in place and the owner has not asked for it to be removed. Download links are issued only after your own license agreement is confirmed.
* Licenses to labs are non-exclusive by default. Terms and pricing are set per engagement.
* RL Tasks license the tasks built from this code, not access to the repositories.
