Source code boundary
ImplementedRepository source, env files, and API keys are not uploaded by the CLI.
Security, privacy, compliance posture, subprocessors, and vulnerability disclosure for the 0dai agentic knowledge layer.
Current release
v4.4.3
Core MCP tools
49
Registered MCP tools
113
Primary data model
Local-first
Compliance
This page distinguishes implemented controls, dogfood enforcement, and planned compliance work. Certification claims appear only after evidence exists.
Repository source, env files, and API keys are not uploaded by the CLI.
Agent work is guarded by issue-first, tasklist, scope, and worktree hygiene checks.
Target H2-2026. Evidence collection and control mapping have started; canonical status line at /security#soc2. ISO 27001 is not claimed and no certification effort is in flight.
The free graph is file-backed today. A paid Postgres/Supabase substrate is planned.
Documents
The first public packet is intentionally small: current public documents, product facts, and a request path for enterprise review.
What we collect, what stays local, and how project telemetry is handled.
Service terms, acceptable use, billing, and account responsibilities.
Activation-first install path and local project wiring.
Free local graph, Pro access, and planned Team cloud graph capabilities.
Public source, issues, pull requests, and release history.
Available by request while the formal trust packet is being assembled.
Security Controls
0dai focuses on the failures that hurt agentic development: secret exposure, repo pollution, unscoped delegation, stale memory, and unreviewed destructive actions.
0dai builds context from manifest files, metadata, and generated ai/ artifacts without sending repository source code by default.
Cloud-facing features start from explicit activation and are constrained by the account plan.
Model provider use is operator-controlled. Customer keys stay in local secret storage when BYOK is used.
Agents are expected to isolate task branches, detect unrelated changes, and keep mergeable work from piling up.
Non-trivial agent dispatch is checked for linked issue, tasklist, profile, scope, plan, and completion proof.
The project runs targeted tests plus security-oriented scans such as secret and dependency checks. Some scans report findings as warnings while gating is hardened.
Operational decisions, memory rule access, and agent activity are recorded into append-only project logs.
Database migrations and destructive actions require explicit human review before execution.
Data Handling
The trust boundary is built around what the CLI needs for project intelligence versus what must remain on the operator machine.
File-backed graph
Secrets stay local
Audit-ready logs
Source files, .env files, credentials, private keys, and raw repository contents stay on the operator machine unless explicitly shared outside 0dai.
Account state, plan tier, CLI version, command outcome telemetry, generated manifest summaries, and support reports may be used for cloud features.
The free product uses a file-backed local graph in the repository. It is designed for inspection and portability.
Paid shared knowledge graph capabilities are planned on a Postgres/Supabase-backed substrate, not shipped as a completed graph database today.
Subprocessors
High-level provider view. The canonical versioned list with per-entry purpose, data category, and processing region lives at /security#subprocessors and is what the DPA points to.
Model inference for agent runs (US-region)
Prompt and tool I/O the operator routes to the selected provider; no source files or secrets
OAuth sign-in where enabled
Identity claims (email, name, avatar) and account linkage
Billing and checkout flows where available
Payment session metadata
Product usage analytics, same host as 0dai.dev
Aggregated web events; no cookies, no user IDs
Production hosting (DigitalOcean) and DNS/TLS/edge (Cloudflare)
Operational logs, account metadata, and service telemetry
Report suspected security issues to hello@0dai.dev. Include impact, reproduction steps, affected versions, and whether sensitive data was exposed.
CLI, website, dashboard, public API endpoints, generated ai/ layer, docs, and agent protocol guardrails.
Social engineering, destructive testing against customer repositories, spam, and high-volume rate-limit noise.
FAQ
Short answers for security reviews, procurement, and teams deciding whether 0dai fits their repo boundaries.
No by default. The public posture is local-first: source files, secrets, and env files are not uploaded by the CLI.
SOC 2 is in progress with a target of H2-2026 — evidence collection and control mapping have started, but no SOC 2 report exists yet and we will not claim certification before one does. ISO 27001 is not claimed and no certification effort is in flight. The canonical status line lives at /security#soc2.
No. The free graph is file-backed today. A paid cloud graph substrate is planned and will be documented separately before launch.
Yes. Email hello@0dai.dev and include the plan, data-flow questions, and procurement requirements you need answered.