Security & compliance

TechDebtRoadmap is a decision-support tool for tech-debt governance. It does not guarantee remediation outcomes, 100% discovery of debt, or legal/compliance certification.

Fail-closed AI (P0)

  • No API key → HTTP 503 AI_NOT_CONFIGURED
  • Quota exhausted → HTTP 429 QUOTA_EXCEEDED before any model call
  • Upstream failure → HTTP 502 AI_UPSTREAM_FAILED
  • Explicit demo → 200 with demo:true and Demo mode banner
  • Live success → 200 with source: 'Model-assisted'

Data handling

Paste only what you need. Redact secrets. Findings are processed to produce your roadmap and are not sold. See Privacy. Payments via Waffo; we do not store card numbers.

Prompt injection awareness

Per OWASP LLM01, treat model-assisted narratives as untrusted text. Prefer deterministic scores and evidence from your scanners for capacity decisions. Ref:OWASP Top 10 for LLM Applications.

(The above is for reference only and is not legal or professional advice. TechDebtRoadmap is decision-support for engineering leaders — it does not guarantee remediation outcomes, 100% coverage of debt, or architectural sign-off. Always review scores against evidence from your own repo scans.)

Was this result helpful?Detailed feedback