CodeSearchGitSecure is a cryptographically isolated search substrate designed to index encrypted Git repositories—spanning source code, markdown documentation, and continuous swarm chat logs—at sub-50ms speeds without ever leaking cleartext to the host filesystem.
Standard open-source search tools assume plaintext. Standard compliance tools enforce security through closed-source, "black box" policy engines (fiat). CodeSearchGitSecure rejects both.
We ensure data sovereignty and security through deep structure: immutable, mathematically sound physical boundaries. Security is not enforced by continuous policing; it is enforced because the cryptographic and memory limits of the system make extraction computationally and physically impossible.
This substrate operates strictly across two low-level operational tiers:
- Level 0 (Granular Storage): Git objects (
blob,tree,commit) are individually wrapped in AES-256-GCM envelopes. - Level 1 (Volatile Search): An in-memory search engine (Zoekt) executes fast positional trigram intersection exclusively within locked
ramfsboundaries.
By relying on physical air-gapping for root trust, HashiCorp Vault for key rotation, and strict volatile memory isolation, this open-source substrate natively aligns with baseline statutory security frameworks (e.g., Japan FSA/CRYPTREC) without relying on proprietary mesh networks.
This repository is currently licensed under the AGPLv3. This provides a temporary, structural defense against proprietary extraction while the open-source community hardens the architecture.
However, our ultimate goal is to merge these modifications upstream into the official Zoekt (Apache 2.0) and Git (LGPL-2.1) repositories. To achieve this, all contributors must agree to a Contributor License Agreement (CLA) that allows us to relicense the code for those specific upstream merges. See CONTRIBUTING.md for details.