Customer-controlled data boundaries
Privacy layer
Source upload
Never by default
Prompt logging
Disabled
Secret handling
Redact before cloud sync
Remote MCP
Requires customer admin approval
Default local-first policy
enabledRepository code
Stays on local machine unless explicitly approved for a run.
Telemetry
Run metadata, validation status, token and cost summaries only.
Retention
30 days for metadata, configurable per customer.
Audit
Every approval, command, integration invocation, and policy override is logged.