Skip to content
Fallow home

Every network call that Fallow makes.

The Fallow Cloud package, @fallow-cli/beacon, counts how often production calls each function. It sends those counts with the function names, file paths and line numbers they belong to. It never sends arguments, return values, request data or user data.

This page is for the security review that comes before the beacon runs in production. It lists every call that the beacon and the free scan make, when each call happens and the exact fields it sends.

The free scan runs on your own machines. Fallow Cloud receives data only when you add the beacon to a service or run an upload command. The analysis sidecar opens no network connection, and local runtime analysis works offline. Check source maps before you upload them, because a source map can hold your original source code.

Each call starts from something you configure or run.

The beacon and the coverage commands send to the endpoint you set. The license commands go to api.fallow.cloud.

  • @fallow-cli/beacon, HTTP mode

    POST{endpoint}/v1/ingest

    When
    The beacon flushes a batch of coverage from a Node, Bun, Deno, serverless or browser runtime that you configured.
    What it sends
    The fields in the tables below, with your API key in the Authorization header.
  • @fallow-cli/beacon, file mode

    No network call

    When
    You configure transport: "fs" and writeToDir.
    What it sends
    Nothing to Fallow. The beacon writes the coverage JSON into the directory you chose.
  • fallow-cov, analysis sidecar

    No network call

    When
    Local runtime coverage analysis starts it.
    What it sends
    Nothing. It reads a JSON request on stdin and writes the analysis as JSON on stdout.
  • fallow license

    POSTapi.fallow.cloud/v1/auth/license/*

    When
    You run fallow license activate, activate --trial or refresh.
    What it sends
    License data: for example your email address, a device code, the current license token or an API key.
  • fallow coverage upload-inventory

    POST{endpoint}/v1/coverage/:repo/inventory

    When
    You or your CI run the command after a deploy.
    What it sends
    The commit SHA and the static function list: file paths, function names, positions, a hash of each function's source text and its complexity scores. When git history is available, it adds per-file churn: commit counts, lines added and deleted, the number of authors and the time of the last commit. With --with-callers, it adds the files that import each function.
  • fallow coverage upload-source-maps

    POST{endpoint}/v1/coverage/:repo/source-maps

    When
    You or your CI run the command after a build.
    What it sends
    The source map files of the build. A source map can hold your original source code in its sourcesContent field.
  • fallow coverage upload-static-findings

    POST{endpoint}/v1/coverage/:repo/static-findings

    When
    You or your CI run the command.
    What it sends
    The commit SHA and the unused exports and dead files that Fallow found, each with its file path, export name and line number.
  • fallow, cloud runtime mode

    GET{endpoint}/v1/coverage/:repo/runtime-context

    When
    You turn on cloud mode for runtime analysis with a flag or an environment variable.
    What it sends
    The repository name and the filters, in the URL. No source code and no syntax tree.

The beacon sends these fields and no others.

The list follows the type definitions of @fallow-cli/beacon. Each request to /v1/ingest has the fields in the first table.

Each request
FieldWhat it holds
AuthorizationThe header with your API key, as a Bearer token.
vThe payload schema version.
batchThe list of coverage payloads.
clientReportsCounts of payloads the beacon dropped, and why. Present only after a drop.
Each payload in batch
FieldWhat it holds
payloadIdA random id, so the server can drop duplicates.
projectIdThe project id you configured.
environmentThe environment name you configured, for example production.
runtimeSurfaceOptional. The name you gave this runtime, for example web or worker.
commitShaThe commit SHA of the deployed build.
timestampThe time of the snapshot.
coverageSourceThe collector that made the payload: v8 or istanbul.
coverageOriginOptional. The origin you set: production, test, ci, build_time or unknown.
functionsOne entry per function, with the fields in the next table.
Each entry in functions
FieldWhat it holds
filePathThe path of the file that holds the function.
functionNameThe name of the function.
lineNumberThe line where the function starts.
columnNumberOptional. The column where the function starts.
endLineOptional. The line where the function ends.
endColumnOptional. The column where the function ends.
stableIdOptional. A short hash that identifies the function.
hitCountThe number of calls in the snapshot.
trackingStatecalled, never_called or untracked.
Each entry in clientReports
FieldWhat it holds
reasonWhy the beacon dropped payloads, for example queue_overflow or network_error.
droppedCountThe number of payloads it dropped.
timestampThe time of the drop.

What the beacon never sends.

  • Function bodies, string literals or other file contents.
  • HTTP request or response bodies, headers, URLs, function arguments or return values.
  • Environment variables, secrets, credentials, heap contents or stack traces.
  • Pings on startup, install counts or diagnostic callbacks.
  • Traffic to a language model provider.

What you control.

  • Runtime collection is opt-in. You configure the API key and the endpoint.
  • The beforeSend hook can change or drop a payload before it leaves the process, and denyPaths leaves out files that match a pattern.
  • Local runtime analysis reads files from disk and never contacts Fallow Cloud.
  • The sidecar checks the license offline, with an Ed25519 public key compiled into it.
  • Cloud mode needs an explicit flag or environment variable. FALLOW_API_KEY alone does not turn it on.

The free scan and its GitHub Action make four calls of their own.

These calls come from fallow and its GitHub Action, not from Fallow Cloud. Telemetry is off until someone turns it on, and the model download starts only after you confirm it. The telemetry page in the docs lists what one event holds.

  • fallow, update check

    GETapi.fallow.cloud/v1/cli/latest-version

    When
    At most once in 24 hours, on an interactive terminal run. It never runs in CI, with --quiet or with machine output such as JSON. FALLOW_UPDATE_CHECK=off or DO_NOT_TRACK turns it off.
    What it sends
    A request for the latest version number, with no data about your code.
  • fallow, product telemetry

    POSTapi.fallow.cloud/v1/telemetry/events

    When
    Only after a person turns it on with fallow telemetry enable. It is off by default.
    What it sends
    Anonymous workflow events. FALLOW_TELEMETRY=inspect prints the exact payload of a run without sending it.
  • fallow similar-code setup, model download

    GEThuggingface.co/jinaai/jina-embeddings-v2-base-code

    When
    You run it and confirm the download.
    What it sends
    A request for the model file. No data about your code.
  • fallow GitHub Action, branded comments

    POSTapi.fallow.cloud/v1/ci/github-token

    When
    A workflow run that grants id-token: write, before the Action posts a pull-request comment. branded-token: false turns it off.
    What it sends
    The short-lived GitHub Actions OIDC token of the run. It names the repository, the workflow and the commit. Fallow returns a GitHub App token for that repository only.

Legal terms and a security contact.

Fallow Cloud is hosted in the EU: the API and database run in Amsterdam, and stored files and database backups stay in the EU. The subprocessor list names each vendor and where it processes data. Hosted data is kept to run the service and to show your team its analysis.