ENTERPRISE · AUDIT

Defend AI-assisted development with evidence

Local-first by default, human Gates 1 & 2 in the IDE, optional sovereign shared-server path with OIDC — built for security reviews of assisted development. We do not claim SOC 2 certification today.

Human gates (v1.0)

Context Lens before inference. Patch preview and apply gates before repo writes. No silent auto-apply on the assisted path.

Agent accountability Roadmap

Planned MCP tool logging and policy engine for agent assistants. v1.0 accountability is IDE gates + operator audit trails — not MCP production controls.

  • Local-first default — Engine + extension per developer (v1.0)
  • Shared on-prem API server — Docker / Helm pilot with platform ops
  • SSO (OIDC) and role-based access on the shared-server path
  • Operator audit / support-bundle export for pilot reviews
  • SOC 2 evidence collectors (Track B roadmap)
  • Path alignment required for shared server (Remote SSH or mounted monorepo)
  • Optional BYOK hybrid routing with egress redaction (off by default)

Deployment fit for security review

Most regulated pilots start local-first (sovereign Ollama on each workstation). Teams that need a shared GPU host use the on-prem API server with VS Code Remote SSH or a mounted monorepo — not laptop clones pointing at a remote URL without path alignment. We document both models and the limitation in the Trust center.

Need a security questionnaire completed? We provide architecture diagrams, data-flow documentation, and a walkthrough of Gates 1 & 2 for your review process.

Trust center Book a Demo