Your code is your most precious asset
Confidentiality governed by NDA and DPA, no code sent to model providers, proprietary models and, when needed, an isolated (air-gapped) environment.
Your code stays between you and Scriba
Scriba uses no LLM: there is no model provider in the pipeline to send your code to. And the contractual safeguards are in place before we receive a single line.
Nothing sent to model providers
Scriba uses no large language models, neither commercial nor open source. Your code is never sent to third-party model providers, because the pipeline doesn't use any.
Proprietary models, Scriba infrastructure
Specialised models and deterministic components run on Scriba's infrastructure. When needed, the platform can operate in an isolated (air-gapped) environment, agreed in the PoC agreement.
Safeguards signed before any code
A non-disclosure agreement (NDA) and a signed declaration of ownership of the code must be in place before anything is sent. If the package contains personal data, its processing is governed by a data processing agreement (DPA).
What changes compared with an LLM-based approach
Typical behaviour: individual tools may differ.
Code confidentiality
Error control
Dependencies after migration
| Aspect | LLM-based approach | Scriba AI |
|---|---|---|
| Code confidentiality | The code is sent to a third-party model, or requires dedicated infrastructure to run. | Nothing sent to model providers; protection governed by NDA and DPA, with an isolated (air-gapped) environment when needed. |
| Error control | An error can look plausible and go unnoticed. | Disagreement between components triggers an escalation; anything that fails the verification gates is not delivered. |
| Dependencies after migration | API subscriptions to keep evolving the code, or infrastructure to maintain. | None: the delivered code depends on no external models and no infrastructure to maintain. |
From signing the NDA to delivery
Every step has a clear owner. The rules are the same for a PoC and for a full engagement.
- 01Client & Scriba
Agreements before code
NDA and declaration of ownership signed before anything is sent; a DPA if personal data is involved. The execution mode is set in the PoC agreement.
- 02Client
A clean package
Before sending, you remove credentials, production endpoints and real personal data. Test data is anonymised while preserving its shape.
- 03Client
Sent over protected channels
A ZIP or TAR.GZ archive via an expiring link to encrypted storage, or a private Git repository with restricted access.
- 04Scriba
Processing with no third parties
The pipeline runs proprietary models on Scriba's infrastructure, or in an air-gapped environment. No model provider is involved.
- 05Scriba
Traceable delivery
Code, tests, data sets, documentation and validation evidence in a Git repository, with every element traceable to the source.
Verifiable, without taking our word for it
Every element of the migrated system traces back to its origin. That is what allows you, or an external reviewer of your choice, to check the result without having to trust whoever produced it.
COBOL ILE batch on IBM i for a leasing company, migrated to Java 25 / Spring Boot 4.1 with a React 18 / TypeScript front end and SQL Server managed with Liquibase. Bit-perfect validation.
Source → target map
For every program, copybook or data definition: the classes, components and tables derived from it.
Extracted business rules
Each one with a reference to the point in the source it comes from.
Declared technical debt
Stubs, known limitations and external dependencies listed explicitly, never hidden in the code.
Validation evidence
Test results, coverage and quality gates, with a report linking every requirement in test.md to the evidence that it was met.
Change log
Observations from independent reviewers are resolved by Scriba and tracked, change by change.
Let's talk confidentiality before code
NDA, declaration of ownership, DPA and execution mode, including an isolated environment if required, are all agreed before any code is exchanged.