Access and control
Zoruko works inside the repository scope you choose. Audits use limited access, fixes are reviewed as pull requests, and merge control stays with your team.
Zoruko reviews your app code through scoped repository access, proposes every fix as a pull request, and avoids ad accounts, production credentials, and hidden automation surfaces.
Zoruko works inside the repository scope you choose. Audits use limited access, fixes are reviewed as pull requests, and merge control stays with your team.
Zoruko opens scoped pull requests with a written rationale, test notes, and rollback context. Nothing lands without your review process.
We do not ask for Meta or TikTok credentials, ad account permissions, or API tokens. Signal fixes run with the credentials inside your own infrastructure.
Zoruko does not need customer PII or ad platform credentials. Signal monitoring is built around minimized metadata and hashed user fields.
GitHub OAuth tokens are encrypted with AES-256-GCM and can be revoked from GitHub at any time, which immediately cuts repository access.
Monitoring uses event metadata such as type, status, and timestamp. User-level fields are hashed before they leave your infrastructure.
Each workspace, repository, branch, and pull request is scoped separately. Fixes are proposed as code, not hidden automation.
Every audit ranks purchase, attribution, refund, and server event issues so the risky paths are reviewed first.
Every change is visible in repo history, PR descriptions, commits, test output, and the review trail your team already uses.
Connections start from the GitHub installation scope you grant. Zoruko only works inside the repositories selected for review.
A Zoruko audit turns unclear tracking risk into a ranked review queue: what broke, where it lives, who should review it, and which pull request fixes it.
Walk security, growth, and engineering through exactly what Zoruko can read, what it cannot access, and how fixes move through review.
Read moreUse audits to catch missing purchase events, weak dedupe, unsafe refund evidence, and server routing gaps before budgets move.
Read moreNo. Audits start with limited repository access. Fixes are proposed as pull requests from scoped branches so your team controls review and merge.
No. Zoruko does not need Meta, TikTok, or ad platform credentials. It reviews and fixes the code paths that send signals from your infrastructure.
The monitoring model is designed around minimized event metadata. User-level fields are hashed before leaving your environment, and customer PII is not required for signal quality review.
Yes. Repository access can be revoked through GitHub settings. Revoking the GitHub installation cuts Zoruko access immediately.
High-risk changes stay small, reviewed, and explicit. They can ship behind feature flags with test notes and rollback context in the pull request.
Bring engineering, growth, and procurement into the same access model before you connect your first repo.
Talk to us