# What the AI reads, and what it never does

> A static reader that never runs your code is the source of truth about your submission. An optional AI layer can only add explanations on top. The AI cannot execute code, change your game, spend money, ban a player or certify safety, and it sees only bounded, redacted facts.

*NetCraftGames (NCG) by Charging Bull Software. Last updated: 2026-10-03. Canonical page: https://netcraftgames.com/trust/*

## The short answer

NetCraftGames separates **reading** from **deciding**. Reading your submission is done by a static, bounded reader that matches fixed patterns and executes nothing. An optional AI layer sits on top: it can explain what the reader found, but the reader is the source of truth. Every pass or fail decision, every limit and every charge is made by ordinary deterministic code. The AI has no tools.

> **Plain wording on "AI reads your code"**
>
> Our tagline flow says an AI reads your code. Precisely: a static reader extracts the networking surface (engine, transports, ports, settings, health endpoint, save paths); AI may explain what it found. We would rather say that than overstate what an AI does.


## What is read

| Reader | What it looks at | How it is bounded |
| --- | --- | --- |
| Static reader | Archive entries, config and script text, embedded strings in binaries, file names that show a Unity player layout, and the glibc version numbers a Linux program declares it needs; engine, transports, ports, settings, health route, save paths, admin interface, embedded credentials | Limits on entries, file sizes, lines and findings; never extracts to disk, compiles, executes or fetches over a network |
| Archive inspector | Archive metadata without extraction | Blocks traversal, links, special permission bits, oversize and compression bombs; text scan limited to selected files |
| Optional AI layer | Bounded, redacted facts | Needs account opt-in and operator enablement; no tools; output validated against a strict schema |

## What the AI never does

- **Never executes your code** on the NetCraftGames control servers, and has no way to run anything.
- **Never changes your game or your project.** Configuration changes are proposals touching an allowlist of existing network and runtime settings, and you apply them. Proposals never add scripts or networking code.
- **Never buys capacity, spends money or sends email.** Billing, reservations and notifications are deterministic code.
- **Never bans or reports a player.** Player reports go to a review queue for a human.
- **Never certifies that your game is safe, fair or bug-free.** Output that claims code safety is rejected, and a passed static scan is not a sandbox or an antivirus guarantee.
- **Never gets high confidence.** Its results can only be marked low or medium, and are shown as advisory next to the original evidence.
- **Never has the last word.** Original evidence stays authoritative.

## What the AI is shown

When you opt in to AI analysis of an incident, the model receives at most twelve short facts: a redacted incident title and recorded facts, each limited to 1,000 characters. You can preview the exact text before anything is sent. It is **not** sent: email addresses, account names, payment data, build archives, source files, manifests, command lines, environment variables, runtime credentials, artifact URLs or raw log collections. Redaction removes URLs, common credential assignments, private-key blocks, tokens, email and IP addresses, but pattern redaction cannot catch everything, so do not paste secrets into incident text. Opting out stops new disclosure; it cannot recall a request already sent.

## Secrets you did not mean to ship

If a credential is found in your upload, the report names its kind, file and variable, never its value. Values are not stored. You are told to rotate it, and where your code reads a secret from an environment variable, you supply the value in a write-only slot. If your game declares an admin or RCON interface that reads its credential from a declared variable, one random credential is created for the game and shown to you once. It stays the same every time your server wakes until you rotate it. We keep a hash to check it and an encrypted copy so every start can use the same value; the copy is deleted when you rotate or erase the game, and it is never shown again, emailed or sent to an AI model. If you lose it, rotate to get a new one.

## Isolation, as designed

- One isolated virtual machine per running game; no customer code runs on the controller.
- Game processes run unprivileged with resource limits; workers carry no cloud role and cannot read instance metadata.
- Customer records are scoped by tenant. Uploads and probes use bounded, validated inputs.

## What is not proven yet

> **Be skeptical of any security claim that has no evidence**
>
> These designs are implemented and tested locally. They have **not** been through an independent penetration test, and the guest isolation, firewall and storage-limit controls still need acceptance testing on real Linux machines. NetCraftGames holds no security certification. The launch checks that cover this are listed on the [status page](https://netcraftgames.com/status/).


## Frequently asked questions


### Does an AI read my game's source code?

A static reader reads the files you submit to find your networking setup, and it never executes anything. An optional AI layer can add explanations on top, but the reader is the source of truth. Nothing you submit runs on NetCraftGames control servers, and AI never decides whether a build passes.

### Can the AI change my game or spend my money?

No. The AI has no tools. Configuration changes are proposals limited to allowlisted network settings that you review and apply. Billing, capacity and notifications are deterministic code with their own limits. The AI cannot buy hours, ban players, send email or certify that your game is safe.

## Related pages

- [What happens when a connection fails](https://netcraftgames.com/connection-failures/): When your game does not connect, NetCraftGames emails the exact problem and a concrete fix, then you resubmit. The 19 failures it detects and how each is fixed.
- [How NetCraftGames takes your game online](https://netcraftgames.com/how-it-works/): How NetCraftGames takes your multiplayer game from submission to a running server in 24 hours: submit, AI reads, connection config, deploy, players join.
- [NetCraftGames fact sheet](https://netcraftgames.com/facts/): The canonical, dated fact sheet for NetCraftGames: what it is, who it is for, prices, limits, supported engines, what is not supported, SLA wording and contact.
