Security and privacy
Version: 2.14 | Last updated: 2026-10-02
Bluebox reads live telemetry and code to investigate production issues. This page explains what it accesses, what it stores, who can see it, the boundaries it never crosses, and how to remove your data.
What Bluebox reads
| Data source | What Bluebox reads | Purpose |
|---|---|---|
| GitHub | Repository code, file trees, commits, pull requests, issues | Investigation context and publishing investigation results |
| Observability platform | Traces, logs, metrics, events, service topology, problem records | Detecting findings and diagnosing root causes |
| Your workspace | Investigations you create, chat messages you send | Running investigations and conversations |
| Your CLI | Which commands the bluebox CLI calls, the CLI version, whether a coding agent drove it and which, a random journey id that ties one run's calls together, and how a run's question ended—completed, failed, timed out, cancelled, out of quota, parked awaiting a response, or the connection closing early | Knowing whether a multi-step run such as instrumentation completed, stalled, or failed, and how long it took |
Bluebox does not read:
- Secrets, environment variables, or
.envfiles in your repositories. - Files outside the repository you have explicitly connected.
- Your prompts, file paths, or output through the journey record: the journey id is random, and the per-call journey record carries the command's route pattern, not its arguments. On an instrumentation run the CLI also sends the address of the repository's
originremote in a reduced form (host and path only - never credentials, branches, or file paths), and the record keeps only a keyed one-way hash of it, scoped to your workspace, so a run can later be matched to the telemetry that repository emits and to nothing else. Nothing in the repository is read for this. - Observability data outside the environment you have connected.