Security & compliance
TechDebtRoadmap is a decision-support tool for tech-debt governance. It does not guarantee remediation outcomes, 100% discovery of debt, or legal/compliance certification.
Fail-closed AI (P0)
- No API key → HTTP 503
AI_NOT_CONFIGURED - Quota exhausted → HTTP 429
QUOTA_EXCEEDEDbefore any model call - Upstream failure → HTTP 502
AI_UPSTREAM_FAILED - Explicit demo → 200 with
demo:trueand Demo mode banner - Live success → 200 with
source: 'Model-assisted'
Data handling
Paste only what you need. Redact secrets. Findings are processed to produce your roadmap and are not sold. See Privacy. Payments via Waffo; we do not store card numbers.
Prompt injection awareness
Per OWASP LLM01, treat model-assisted narratives as untrusted text. Prefer deterministic scores and evidence from your scanners for capacity decisions. Ref:OWASP Top 10 for LLM Applications.
(The above is for reference only and is not legal or professional advice. TechDebtRoadmap is decision-support for engineering leaders — it does not guarantee remediation outcomes, 100% coverage of debt, or architectural sign-off. Always review scores against evidence from your own repo scans.)