trust

We keep the numbers. Never the prompts or the code.

Enterprises will not let their code or prompts be seen or kept. That is a precondition, not a feature, so the architecture says it precisely: stream, don't store; aggregates leave the laptop and raw data does not; the things that must carry content are opt-in, encrypted and expiring.

0 prompts or coderetained by the proxy. Tokens, model, cost, when, the decision. No bodies.
3 exceptionsthat carry content — the hand-off snapshot, the estimate body, the intake brief — each yours to turn off.
7 daysbefore a hand-off snapshot expires on its own.
what we see and what we keepthe proxy · the record · the tracker
surfacepasses throughkeptnever
the proxyRequests to your own Claude or OpenAI seat, and back.Tokens, model, cost, when, the seat, the decision at the wall.Prompt or completion bodies. Repo contents. Tool output.
the recordThe PR body's SLEDS-* lines, the ticket's fields, the brief.Estimate, worth, actual, receipt, brief, per row.The diff. The spec body, once the estimate is recorded.
the seat readerYour own usage page, read as you.Percent per bar, credits, the reset.Anything else on the account.
the connectorWhat your AI sends to the tools: the ask, links, a stated worth.The brief, as confirmed by you. Sources as links.The rest of your conversation.
the tracker and SlackWhat they already show you.Nothing beyond what we wrote there.Membership, permissions, message history.
the exceptionsall switchable · all expiring

Three features carry content because they cannot work without it.

The hand-off snapshot

A hand-off parks the conversation for a teammate so they can continue where you were. Encrypted at rest, decrypted on pickup, expired after seven days or on withdraw. Off per workspace or per seat.

The estimate body

The spec body is read once and the band is recorded; the body is not kept. Off per workspace, in which case rows are sized from the ticket's title and history only.

The intake brief

The ask, the why, done, the smallest version, in the requester's words. Stored on the row, encrypted, expiring with the row's retention. Sources stay links to where they already live. Opt-in per workspace.

Sensitivity becomes a dispatch constraint: a workspace can say which work may run on which rail, and restricted work never leaves the seats you name.

self-hostyour keys · your region · your logs

Run it where your review says it has to run.

The proxy is a small service. Enterprise workspaces run it — and the record, and the connector — in their own account or region on their own keys, with our control plane seeing only what the record needs. Identity comes through WorkOS: SSO, SCIM, MFA and an admin portal, one connection, nothing built by hand. Self-host, in full →

Keys

Platform keys stay in your vault. The proxy holds them; the control plane never does.

Audit

Every policy decision, grant and admin action lands in the audit log, visible to the person it concerns.

The receipt

Ed25519 with the workspace's key. Verified locally with the public key; nothing to trust us for.

Leaving

Uninstall removes every trace from the laptop. Your tracker keeps the rows we wrote. They are yours.

what we don't buildneutrality is the product

Our own coding agent. A tracker with a head. A gateway. Model access. Anything that ranks people.

An enterprise will run several agents on several platforms. The layer that dispatches across them and keeps one set of books has to be independent of all of them: no interest in where the work runs, no cut of what it routes, no system of record taken by force. The customer's agents, models, keys and trackers are theirs. We are the layer that makes them one set of books.

Stream, don't store.

$sleds verify <receipt line>
checked locally against the workspace's public key · privacy →