Repo exfiltration is not part of the base design.
AGENTS.md, memory, skills and hooks live locally. AI providers depend on the plan and integration the customer activates.
Cardumen is designed for real repos with intellectual property, NDAs and teams that cannot paste secrets into prompts.
AGENTS.md, memory, skills and hooks live locally. AI providers depend on the plan and integration the customer activates.
The signature is checked in milliseconds outside the network hot path. If it cannot be verified, the system stops.
The harness protects destructive operations and requires explicit confirmation for deployments, migrations or high-risk changes.
Sensitive teams can run dedicated capacity in their office with managed hardware and clear custody conditions.
Not by default. Cardumen is local-first: rules, memory, skills, hooks and verify live in your repo and machine.
The license is cached locally and validated offline with an Ed25519 signature. There is no fail-open path when the signature cannot be verified.
The decision engine and sensitive harness artifacts are decrypted per session with an active license.
Yes. Factory On-Prem installs dedicated private capacity for teams with NDAs and sensitive data.
CLI Core, Local and Factory cover different privacy levels. The route depends on data, hardware and compliance.