DesnarlDesnarl
Desnarl

Security & architecture

What actually leaves your network.

Desnarl reads your repos on your own infrastructure. This page names every real exception to that, plainly, with nothing implied and nothing left out.

Two ways Desnarl runs

The architecture differs by mode. Both keep your repo content on your own infrastructure.

Interactive, local workspace

Desnarl reads sibling repos checked out on disk and makes no network calls at all in this mode.

Self-hosted, persistent instance

Storage and compute still run entirely on your own infrastructure. This mode adds a narrow, named set of network calls, listed below. Nothing outside that list is ever called.

The four network exceptions

This is the complete list. If a call is not named here, Desnarl does not make it.

Network callStatus

Registry lookups

A read-only call to registry.npmjs.org to resolve a declared package version against what is actually published. npm only — there is no equivalent call for any other package ecosystem, and no Python support.

registry.npmjs.org

Shipped

Repository ingestion

A scheduled git clone and fetch of your own repos from github.com and api.github.com, authenticated with a deploy key you hold. This is a real network clone of your repos into your own self-hosted instance, not a metadata-only call.

github.com, api.github.com

Shipped

License check-in

A periodic check that your license key is valid. This call is designed but not live yet, so treat it as not happening today.

Not live yet

Alert webhook

An optional, off-by-default outbound message to Discord or Slack when a repo index goes stale. The alerting code is built but is not sending anything from a released instance yet.

discord.com, hooks.slack.com

Built, not yet active

Every call re-checks redirects

Every one of these calls sets redirect to manual and re-validates the redirect target against the same allowlist. None of them silently follows a redirect off the allowlisted host.

How far it reaches into your code

A tool that traces relationships across a whole codebase should say how far it actually goes.

Traversal depth is a caller-tunable parameter, not a fixed ceiling. A query traces as many hops as it asks for and stops there — there is no background crawl and no continuous graph maintenance. The shipped default is 4 hops. Depth only changes how much of your own code is read on your own infrastructure; it sends nothing to Desnarl or to any third party.

A real four-hop chain

This dependency chain in the Kubernetes ecosystem is a real, measured four hops end to end, and it resolves in full at the shipped default of 4 hops.

k8s.io/api

k8s.io/apimachinery

k8s.io/client-go

k8s.io/apiserver

kube-aggregator

4 hops

Data custody

Storage and compute run on your own infrastructure, and Desnarl never holds your repo content. Account signup and the optional alert and check-in traffic above are still standard SaaS-signup data processing: GDPR exposure is reduced to standard SaaS-signup scope, not eliminated.

Support is not email or a public forum

Support runs through the license portal only: create an account, sign in, and file a ticket. There is no channel outside the portal, and no public forum. Filing a ticket is not available yet — the portal itself is live, but that part of it is still being built.