The outcome
Make an evidence-based adoption decision without exposing confidential source code during evaluation.
Step by step
A workflow you can repeat.
- 01
Define pilot tasks, prohibited data, quality and latency measures, acceptable regions and retention, required controls, and an exit procedure.
- 02
Use a synthetic or public repository and isolated account, review current privacy terms, enable Privacy Mode, and record relevant settings and version.
- 03
Run representative completion, chat, and agent tasks while observing files selected for context, network activity, extensions, commands, model behavior, and cost.
- 04
Measure correctness, tests, dependency hygiene, prompt-injection resistance, telemetry reduction, index deletion claims, and behavior after account or project removal.
- 05
Document gaps and compensating controls, obtain security and legal approval where needed, and keep sensitive repositories out until every requirement passes.
Working standard
What good use looks like.
- Pilot with non-sensitive code.
- Review current terms, not marketing summaries.
- Verify deletion and telemetry behavior.
Official references