This page is our standing answer to the reasonable question: “you want access to our code?” Short version: less access than a new hire gets, more paper trail than most contractors offer.

Access model

  • We work on a fork or on feature branches only. You keep merge rights; we never push to your main branch.
  • No production credentials, no production databases, no customer data. Reproductions run on local fixtures.
  • Access is granted per engagement, per named account, and is yours to revoke at any moment.

Legal

  • NDA signed before we see a line of code. Yours or ours, whichever is faster.
  • Each engagement runs on a short written agreement: scope, price, IP assignment of the delivered work to you.
  • For first engagements we are happy to work through an escrow platform, so payment and delivery are both protected.

People and agents

  • Implementation is done by AI agents running in an isolated environment under our orchestration stack.
  • Every diff is reviewed by a named senior engineer before it reaches you. The engineer is accountable for the work, not the bot.
  • Agent access to your repository is scoped exactly like human access: branch-only, revocable, logged.

Data handling

  • Your code stays in your repository. We do not mirror it to third-party services.
  • Briefs, notes, and run artifacts are stored on infrastructure we control, in the EU.
  • On request at the end of an engagement, we delete retained artifacts and confirm in writing.

Start with the 5-bug pilotQuestions? Write to us

© 2026 Bointsoft, Skopje. Merged pull requests, not hours.