Run AI coding where the data is not allowed to leave
Residency obligations, contracts and sector rules decide whether code can leave, and that answer arrives before anyone discusses capability.
The boundary question is asked before the capability question
A security review begins with where each part runs, what leaves, and who operates the parts that stay. A vague answer there ends the evaluation.
That has to hold for verification too. A verifier calling a hosted judge reintroduces what the deployment existed to avoid.
Meeting the condition is a specification, not an advantage
Nothing vendor-operated
No component of the deployed product is run by anyone but you.
No second dependency
The scorer uses no second model, no hosted judge and no API call, so verification adds nothing external.
Inspectable rather than described
The mechanism is readable under AGPL-3.0, an OSI-approved open-source license.
What runs between the request and the answer
Proposal
The change your agent proposes enters the write path as candidate zero, the baseline.
Alternatives
Several candidates are generated instead of the first answer being accepted.
Execution
Each runs in an isolated sandbox against the project's available checks and the runtime's own oracles.
Guarded write
An alternative must earn authorization to replace the baseline. What did not earn it carries no verification metadata.
Failures return to step 02 as repair input rather than starting over
Proposal, alternatives, execution, guarded write, with repair feeding back.
Where the boundary decides the outcome
Regulated sectors
- The work
- Building on codebases governed by sector rules on data handling.
- What repeats
- Every tool evaluation restarts at the same question about where source and prompts go.
- What changes
- One answer that holds for the model, the sandbox, the test run and the logs, all on machines you operate.
Residency obligations
- The work
- Working under terms that fix where data may be processed.
- What repeats
- Hosted assistance is ruled out before its capability is assessed.
- What changes
- The whole path sits inside the environment, so the obligation is met by the architecture rather than by a contract clause.
Vendor and supply-chain review
- The work
- Passing procurement rather than working around it.
- What repeats
- Each added service is another vendor to assess, and verification usually adds one.
- What changes
- Verification introduces no new external dependency, so the assessment surface does not grow.
Other solutions
Get more out of the models you are allowed to run
Built to raise the reliability of whichever model your policy permits, rather than asking you to change it.
Read the solutionGive the teams that had to go without an approved path
Whole units have gone without AI assistance because no approved path existed. This is one.
Read the solutionTalk through your deployment constraints
The repository and the docs need no form. This one scopes a deployment.