Security and privacy

LogiKFlow is built to see no more than you can, and to store as little as possible.

Access

  • Your permissions, not the app's. Every request to GitHub uses your own token. You see only repositories and pull requests your account can see.
  • Writing an order requires write access. LogiKFlow asks GitHub for your permission on the repository before every save.
  • Private repositories need the app installed. The owning account or organization decides which repositories the LogiKFlow GitHub App can reach, and can remove it at any time.

What the GitHub App can do

PermissionWhy
Contents: readShow diffs of changed files
Pull requests: read and writeRead pull requests; write only to post the review link as a comment when you choose Post to PR
Metadata: readRequired by GitHub for every app

LogiKFlow never pushes code, changes branches or approves pull requests.

What's stored

DataPurpose
Your GitHub user ID, login and avatar URLShow who saved an order or ticked an item
Sessions: a hash of the session token and your GitHub tokens, encryptedKeep you signed in
Reading orders: file paths, section titles, notes, checklist text, and each versionThe feature itself
Viewed files and checklist ticksYour review progress
Recently opened pull requests (repo, number, title)Your dashboard

LogiKFlow doesn't store source code or diffs. They're fetched from GitHub when you open a pull request.

How it's protected

  • GitHub tokens are encrypted with AES-256-GCM before they're stored. Session cookies hold a random token, and only its SHA-256 hash is stored.
  • Cookies are __Host- prefixed, HttpOnly, Secure and SameSite=Lax.
  • Every change must come from the LogiKFlow site itself and be sent as JSON, which blocks cross-site request forgery.
  • A strict Content Security Policy, HSTS and nosniff are sent on every page.
  • Agent connections use OAuth 2.1 with PKCE and a consent page that can't be framed or forged, and follow the MCP authorization specification.
  • Requests are rate limited per person.

Signing out and disconnecting

  • Sign out on any page ends the session and deletes it.
  • To disconnect an AI agent, remove the LogiKFlow server from the agent.
  • To revoke LogiKFlow entirely, go to GitHub โ†’ Settings โ†’ Applications โ†’ Authorized GitHub Apps.
For LLMs and agents: This page as Markdown llms.txt llms-full.txt