Your repo stays yours

Test Maze verifies the work without ever reading your code. Here is exactly what stays on your machine and what your agent sends us.

YOUR REPO STAYS YOURS

We verify the work.
We never read your repo.

Your repository lives on your laptop, in your IDE, with your own LLM. Test Maze has no access to it and only sees what your agent explicitly sends in a tool call: test artefacts, run results and git identifiers — plus a snippet of code only when you ask for a code-quality check.

ON YOUR MACHINE

Stays right here.

Your repository
.ts / .py / .go / .sql — whatever the agent edits stays on disk. Test Maze never clones, pulls or scans it.
.env, secrets, credentials
We never read your environment. Your secrets are not in scope.
The LLM that powers your IDE
Claude / GPT / Gemini runs in your client. We never proxy LLM traffic.
Rendered prompt output
feature-spec and ac-to-testcase expansions execute client-side. The diff between template and rendered prompt never reaches us.
Git diffs & history
Test runs carry the commit sha, branch and a clean-working-tree flag — identifiers, not contents.
REACHES TEST MAZE

Just the verdict layer.

Test case rows
Titles, AC labels, steps, expected results — the contract your code is built against.
Test run results
Pass / fail status per case, failure-bucket classification, KPI scoring.
Git identifiers
gitSha, branch name, workingTreeClean flag. We pin verdicts to revisions, never to file contents.
Evidence — opt-in only
Screenshots attach to a run only when your agent explicitly sends one with its results.
Code you ask us to review — opt-in only
quality.smell_check analyses the snippet or diff your agent passes, with fixed rules and no AI. Exploratory testing sends page snapshots of the app under test.
Tool-call trace
Every call (long inputs truncated, secret-looking keys masked) shows on Agent Sessions inside your workspace only. Per-workspace tmt_* tokens isolate every customer.
Point it at your own Test Maze deployment.

The @testmaze/mcp client talks to whichever serverTESTMAZE_MCP_URLnames, so a private deployment keeps the whole verifier loop inside your perimeter.

BYOK AI keys AES-256-GCM encrypted· Per-space tmt_* tokens· Multi-tenant isolation

Ready to give your agent a verifier?

Create a free workspace, generate an MCP token and connect your coding agent in under five minutes.