Posthook records AI coding activity and links it to Git commits. In team mode, Bilanc receives and stores individual records and content, not just aggregate metrics: engineer identity, repository and file metadata, session details, prompts, agent-hook payloads, commits, and line-attribution records.
There are three distinct places to consider in a security review:
Prompts and hook payloads are not automatically redacted before storage or team sync. They can contain source code, commands, tool responses, credentials, personal information, or other confidential content. Do not treat Posthook as a metadata-only collector or deploy it into a restricted environment on that assumption.
Capture scope
Posthook installs hooks in the detected agents’ user-level configuration and places a Git shadow ahead of the real git executable on PATH. On laptops, supported agents are Claude Code, Cursor, and Codex CLI. Cloud agents, including Devin, use their own hook configuration.
Capture is not restricted to repositories connected to Bilanc: hooks can record agent activity across the user’s workspaces, and commits made through the Git shadow are recorded without per-repository setup. The exact events and fields available depend on the agent, its version, and which hooks fire. Posthook also reads edited files locally to compute line ranges and supported agents’ local transcripts to extract prompts, model information, session times, and token usage.
Data inventory
The following records are stored locally and included in team sync when enabled. Identifiers and timestamps accompany records to link sessions, events, repositories, and commits. Fields unavailable from an agent or Git may be empty.
What can be inside a hook payload?
Posthook stores the payload supplied by the agent, rather than projecting it down to a fixed set of safe fields. Depending on the hook, this can include:
- Tool names, inputs, and responses supplied by the agent.
- Source-code fragments such as an edit’s
old_string and new_string, patches, or the complete content passed to a file-write tool.
- Shell commands and any outputs present in the payload.
- Prompt text, local transcript paths, and other agent-specific metadata.
- The final assistant reply in
last_assistant_message when supplied by a Stop hook. Bilanc uses this to display assistant replies alongside user prompts.
Reading a file for attribution is not the same as uploading an entire repository snapshot. However, file contents can still be stored and uploaded through tool payloads and prompts. Likewise, extracting prompts from a transcript does not mean every agent’s entire conversation transcript is collected. The raw payload remains part of the stored data even if a field is not shown in the dashboard.
Where data is stored
On the machine
~/.posthook/posthook.db is the local SQLite database. Posthook does not encrypt this database at the application layer; protect it with your endpoint access controls and disk-encryption policy.
~/.posthook/spool/ temporarily holds raw hook payloads before the worker ingests them. Successfully processed records are removed from the spool; failed records can remain for retry.
~/.posthook/config.json holds cloud-sync settings, the team install token, and configured engineer identity. The configuration writer uses owner-only file permissions (0600), not encryption. Runtime environment variables can supply or override these settings instead.
- Each tracked repository can contain attribution metadata under
refs/notes/posthook.
Treat the local database, spool, configuration, and any endpoint backups as sensitive. In a cloud-agent setup, these locations are on the agent vendor’s session machine, not the engineer’s laptop.
In Bilanc
Team sync sends pending rows as JSON to POST /posthook/ingest. The standard hosted endpoint is https://api.bilanc.co/posthook/ingest, using HTTPS and a Bearer install token. A custom endpoint uses the URL configured for that deployment; ensure it uses HTTPS.
The ingestion service stores the complete batch in PostgreSQL, associated with the organization identified by the validated install key. Raw batches are append-only: retries or updated records can produce additional batches. Bilanc then derives session, message, file, commit, and aggregate views from those records. Raw storage is not limited to the fields or aggregates visible in the dashboard.
Cloud sync does not remove the local copy. When sync is first enabled or resumed, previously captured, pending records can be uploaded too; enabling it is not a “collect only from now on” boundary.
In your Git remote
Git-note sharing is separate from Bilanc ingestion and does not require an install key. Notes contain the commit SHA, repository-relative file paths, line ranges, agent, model, session ID, and event timestamps. The Posthook-generated notes do not contain prompt text or source-code snippets.
The Git shadow pushes these notes after a successful git push and fetches/merges them during relevant Git operations. They are subject to your repository host’s access and retention controls, and can be copied into other clones. “Local-only” means no Bilanc team upload; it does not, by itself, disable Git-note sharing or the network downloads used for installation and updates.
Authentication and access
- A Bilanc Owner or Manager can create, list, and revoke team install keys.
- An install key is organization-scoped and write-only for Posthook ingestion. It does not grant access to Bilanc’s user or metrics read APIs. The ingestion service derives the destination organization from the key, not a tenant supplied in the payload.
- Engineers do not need Bilanc accounts to send records with an install key. Engineer names and emails are attribution metadata supplied by the client, not individual authentication credentials.
- Dashboard and metrics access uses Bilanc user authentication and permissions, separately from the install key. See user management and Posthook metrics for the documented role and data-access model.
Keep install links and tokens in your organization’s secrets-management system. One key can be shared by multiple machines; revoking it stops future authorized uploads using that key, not just one engineer’s uploads.
Controls and their limits
Pause Bilanc uploads
The running sync loop reloads configuration on subsequent cycles. This does not cancel an upload already in flight. Environment overrides take precedence over the configuration file: remove or disable POSTHOOK_CLOUD_ENABLED in the service or hook environment too if it enables sync there, especially for cloud-agent plugins.
Pausing sync does not stop local capture, delete local or hosted records, or prevent pending records from uploading if sync is re-enabled. Revoking an install key is an additional server-side control on future uploads.
Disable automatic Git-note sharing
Set this in the environment used by Git invocations, including cloud-agent sessions where applicable. It disables the Git shadow’s explicit note fetch/merge operations and automatic note pushes, not local note creation or a user’s explicit Git commands. It does not remove notes already present in remotes or clones.
Ordinary Git fetches can still download notes. Posthook adds a persistent fetch refspec to Git configuration; the environment setting does not remove it. If note downloads must stop too, edit each affected repository’s Git configuration and remove Posthook’s +refs/notes/posthook*:refs/notes/posthook-remote* value from every affected remote.<name>.fetch entry. Older installations may instead have +refs/notes/posthook:refs/notes/posthook-remote or refs/notes/posthook:refs/notes/posthook; remove those note-fetch entries too, leaving normal branch fetch entries intact. Recheck after installation or posthook notes configure, which can add the refspec again even with the environment setting disabled. The fallback post-commit hook also runs that configuration command.
Restricted repositories and deletion
The current sync path has no content-redaction or per-repository upload filter. Dashboard filters are not collection controls. If you need exclusions or a metadata-only mode, agree a supported approach with Bilanc before enabling capture or sync; do not assume those controls are included in a standard install.
Disabling uploads, uninstalling the sync daemon, or revoking a key is not a data-deletion request. Hosted deletion must address raw batches and derived data; local copies, backups, and Git notes are separate locations to consider. Contact Bilanc to confirm the applicable retention and deletion process for your deployment.
Enterprise review checklist
This page describes the collector and ingestion behavior; it is not an assurance of certification or a substitute for your agreement with Bilanc. Before approving a rollout, request confirmation of:
- Hosting region, data residency, and any cross-border transfers for your deployment.
- Hosted encryption-at-rest and key-management controls, including backups.
- Retention periods and deletion procedures for raw batches, derived records, logs, and backups.
- Who can access data, including support or administrative access, and the applicable audit controls.
- The current subprocessor list, DPA, any AI-processing or model-training terms, and compliance reports required by your organization.
- Your endpoint policy for local data, install tokens, cloud-agent machines, Git-note sharing, and sensitive repositories.
Ask your Bilanc contact for these deployment-specific and contractual details. Do not infer a retention period, a no-training commitment, or a certification from the collector’s behavior.
Implementation reference
This inventory was checked against the open-source collector at revision 017b1c8: local schema, capture, and sync. Check posthook version and review your deployed version and agent configuration when using this page for an assessment.