Security

Your code stays where your agents run.

Fleet separates coordination from execution. The control plane knows the state of the work. The customer-controlled runner holds the code, model keys, worktrees, transcripts, and local artifacts.

Fleet control plane

Coordinates

Member and workflow state

Branch, CI, and review references

Decision log and actors

Runner liveness and integration health

Usage counters and budget state

Customer execution plane

Executes

Source code and diffs

Agent prompts and transcripts

Model provider keys

Worktrees and local artifacts

Long-lived runner credentials

Structural controls

Security by system shape.

Outbound-only runner

The runner polls Fleet for work. Customer repositories and development machines do not require inbound ports.

Short-lived forge access

GitHub and GitLab credentials can be minted per member and repository, kept in memory, and revoked when the member is fired.

Open trust anchor

The runner and wire protocol are Apache-2.0 so the code operating beside repositories and model keys can be inspected.

Claim-check artifacts

Workflow messages carry references and hashes instead of moving source, diffs, prompts, or transcripts through the control plane.

Private preview

Keep your coding tools.
Give them one engineering system.

Fleet is prelaunch and not accepting accounts yet. Join the private-preview waitlist or explore the product and security model.

Join the waitlistReview security