Pre-launch.NetCraftGames is not accepting customers yet. Launch happens only after its public checks pass.See launch statusJoin the waitlist

Trust and security

What the AI reads, and what it never does

A static reader that never runs your code is the source of truth about your submission. An optional AI layer can only add explanations on top. The AI cannot execute code, change your game, spend money, ban a player or certify safety, and it sees only bounded, redacted facts.

By Charging Bull SoftwareLast updated:

The short answer

NetCraftGames separates reading from deciding. Reading your submission is done by a static, bounded reader that matches fixed patterns and executes nothing. An optional AI layer sits on top: it can explain what the reader found, but the reader is the source of truth. Every pass or fail decision, every limit and every charge is made by ordinary deterministic code. The AI has no tools.

What is read

ReaderWhat it looks atHow it is bounded
Static readerArchive entries, config and script text, embedded strings in binaries, file names that show a Unity player layout, and the glibc version numbers a Linux program declares it needs; engine, transports, ports, settings, health route, save paths, admin interface, embedded credentialsLimits on entries, file sizes, lines and findings; never extracts to disk, compiles, executes or fetches over a network
Archive inspectorArchive metadata without extractionBlocks traversal, links, special permission bits, oversize and compression bombs; text scan limited to selected files
Optional AI layerBounded, redacted factsNeeds account opt-in and operator enablement; no tools; output validated against a strict schema

What the AI never does

  • Never executes your code on the NetCraftGames control servers, and has no way to run anything.
  • Never changes your game or your project. Configuration changes are proposals touching an allowlist of existing network and runtime settings, and you apply them. Proposals never add scripts or networking code.
  • Never buys capacity, spends money or sends email. Billing, reservations and notifications are deterministic code.
  • Never bans or reports a player. Player reports go to a review queue for a human.
  • Never certifies that your game is safe, fair or bug-free. Output that claims code safety is rejected, and a passed static scan is not a sandbox or an antivirus guarantee.
  • Never gets high confidence. Its results can only be marked low or medium, and are shown as advisory next to the original evidence.
  • Never has the last word. Original evidence stays authoritative.

What the AI is shown

When you opt in to AI analysis of an incident, the model receives at most twelve short facts: a redacted incident title and recorded facts, each limited to 1,000 characters. You can preview the exact text before anything is sent. It is not sent: email addresses, account names, payment data, build archives, source files, manifests, command lines, environment variables, runtime credentials, artifact URLs or raw log collections. Redaction removes URLs, common credential assignments, private-key blocks, tokens, email and IP addresses, but pattern redaction cannot catch everything, so do not paste secrets into incident text. Opting out stops new disclosure; it cannot recall a request already sent.

Secrets you did not mean to ship

If a credential is found in your upload, the report names its kind, file and variable, never its value. Values are not stored. You are told to rotate it, and where your code reads a secret from an environment variable, you supply the value in a write-only slot. If your game declares an admin or RCON interface that reads its credential from a declared variable, one random credential is created for the game and shown to you once. It stays the same every time your server wakes until you rotate it. We keep a hash to check it and an encrypted copy so every start can use the same value; the copy is deleted when you rotate or erase the game, and it is never shown again, emailed or sent to an AI model. If you lose it, rotate to get a new one.

Isolation, as designed

  • One isolated virtual machine per running game; no customer code runs on the controller.
  • Game processes run unprivileged with resource limits; workers carry no cloud role and cannot read instance metadata.
  • Customer records are scoped by tenant. Uploads and probes use bounded, validated inputs.

What is not proven yet

Frequently asked questions

Does an AI read my game's source code?

A static reader reads the files you submit to find your networking setup, and it never executes anything. An optional AI layer can add explanations on top, but the reader is the source of truth. Nothing you submit runs on NetCraftGames control servers, and AI never decides whether a build passes.

Can the AI change my game or spend my money?

No. The AI has no tools. Configuration changes are proposals limited to allowlisted network settings that you review and apply. Billing, capacity and notifications are deterministic code with their own limits. The AI cannot buy hours, ban players, send email or certify that your game is safe.