A narrow boundary for checking agent actions.
SelectAgent Verify performs read-only checks against authorized GitHub repositories. It does not create, edit or delete provider records, and it does not automatically retry the original action. Service operators configure access before a connection is used.
Access and credentials.
Requesting early access is free and requires no card. Free access still requires consent, repository authorization and agreed data-handling instructions. Operators issue preview keys; the site does not yet provide self-service accounts, quota metering or usage-credit purchases. Planned credits will be optional, with no automatic upgrade or default charge.
The API requires an operator-issued bearer key. Server configuration maps each key hash to a tenant, actor, permitted operations and connection IDs. Connections restrict repository access. Contract registration, verification and result retrieval enforce those scopes.
Provider credentials are kept in owner-restricted server configuration outside the verification database and API responses. Administrative access is limited to authorized service operators. The hosted service runs on a VPS, with public HTTPS through Cloudflare.
Keep your issued key in a private file or your agent's server environment. Never place it in browser code, a public repository, the access request form or an ordinary support message. Contact us to revoke or replace a key if its confidentiality is in doubt.
What the service stores.
SQLite stores outcome contracts and verification episodes. Contracts include identifiers, repository scope, correlation data and expected fields. Results include field-check outcomes, referenced issue numbers and URLs, timestamps, read coverage and an evidence hash.
GitHub responses, including issue bodies, are processed transiently to locate the marker and evaluate the contract. Full issue bodies are not persisted in verification records. An evidence hash supports checking a recorded result's integrity; it is not an independent third-party attestation.
Deterministic field checks produce the verdict. The verification path does not require a general-purpose AI model or send provider records to a model for judgment. Your calling agent's own model and data-handling choices are separate.
Bounded reads, explicit uncertainty.
Provider requests have configured page, response and time limits. Unavailable access, provider errors or incomplete evidence produce an indeterminate result rather than a claim that no write occurred. A known-resource check does not establish global uniqueness, and a marker does not establish causality.
Verification establishes only the reported observable fields at the recorded time. Workflows remain responsible for deciding what to do next within their granted authority.
Backups and preview readiness.
The current backup configuration keeps the seven most recent local snapshots and performs a restore-integrity check. This is a snapshot count, not a universal seven-day retention period. Automated off-host backups remain pending, so local snapshots do not address loss of the entire host.
Evidence retention and operational requirements are agreed before customer onboarding. The private preview does not advertise SOC 2 certification or a standard uptime SLA. Raise any required controls, data-location restrictions or review documents before authorizing a connection.
Report a security concern.
Email the SelectAgent team with the affected feature, approximate time and a sanitized description. Do not include active credentials or customer records; we can arrange an appropriate way to share necessary details.