Denly

What Denly's servers can and cannot see: encryption and data boundaries

Your source repository is never uploaded to Denly. With workspace end-to-end encryption enabled, task text, plans, conversations and attachments are encrypted before upload and unreadable to Denly.

Repository contents are not uploaded to Denly. When workspace E2E is enabled, task text, plans, conversations, and attachments are encrypted in the browser or runner and unreadable to Denly. Without E2E, coordination text is stored normally so the service can deliver it.

Runner environment
DENLY_E2E_PASSPHRASE=your-workspace-passphrase
Passphrase loss is permanent.Denly cannot recover encrypted history. Your Git host receives pushed code and your chosen AI provider receives the context sent by its CLI under your agreements with them.