Part of #525. From the BYOK security audit.
No docs describe BYOK for maintainers. #648 (onboarding docs) is open and owns docs.github-app.tsx, so add BYOK docs without conflicting (standalone doc / .gittensory.yml reference section, or fold into #648 after it merges).
Content: enabling AI review modes; the gate.aiReview / settings.aiReview config-as-code keys incl. provider/model; BYOK key handling (AES-256-GCM at rest, write-only, never echoed/logged); consensus blocking always uses free Workers AI and only affects confirmed contributors. Link from the maintainer dashboard panel.
Severity: low.
Part of #525. From the BYOK security audit.
No docs describe BYOK for maintainers. #648 (onboarding docs) is open and owns
docs.github-app.tsx, so add BYOK docs without conflicting (standalone doc / .gittensory.yml reference section, or fold into #648 after it merges).Content: enabling AI review modes; the
gate.aiReview/settings.aiReviewconfig-as-code keys incl. provider/model; BYOK key handling (AES-256-GCM at rest, write-only, never echoed/logged); consensus blocking always uses free Workers AI and only affects confirmed contributors. Link from the maintainer dashboard panel.Severity: low.