Local archive
Read-only repository collection and verifiable local evidence archives.
Security, privacy, and deployment
Source code, issue discussions, decisions, incidents, and agent transcripts are sensitive. Privacy and access control are product features, not implementation details.
Local-first default
The first context and anchor implementation is intended to run locally against a developer’s repositories and KodeAtlas archive. This reduces deployment friction, aligns with sensitive-code requirements, and keeps the initial product operable without a centralized service.
Security requirements · Product direction
Agent authorization · Planned
An agent should receive only the repositories, symbols, tasks, and evidence its user and execution context are allowed to access. Claims must bind to a human or service account, branch or worktree, base commit, task, heartbeat, and expiration policy.
An agent must not be able to impersonate another agent or silently extend a claim forever.
Transcript sensitivity · Future ingestion
Transcript ingestion will require secret scanning, configurable redaction, retention, deletion, and a choice between retaining raw text or only extracted evidence. Credentials, customer data, incident details, and uncommitted reasoning cannot be treated as ordinary search documents.
Deployment modes · Product direction
Read-only repository collection and verifiable local evidence archives.
Embedded database, local repositories, local MCP server, and locally controlled artifacts.
Shared repositories, connectors, agent registry, PostgreSQL, object storage, web UI, policy, and audit.
Customer-controlled models, no external code transfer, access policy, retention, and governance.
Take the next step
Sensitive code intelligence should not force a team to surrender control of its source, history, or agent transcripts.