Security

Local privacy first. Enterprise control when you need it.

Cardumen is designed for real repos with intellectual property, NDAs and teams that cannot paste secrets into prompts.

Local-first

Repo exfiltration is not part of the base design.

AGENTS.md, memory, skills and hooks live locally. AI providers depend on the plan and integration the customer activates.

Ed25519

License verification works offline.

The signature is checked in milliseconds outside the network hot path. If it cannot be verified, the system stops.

Policy guard

Dangerous commands are blocked.

The harness protects destructive operations and requires explicit confirmation for deployments, migrations or high-risk changes.

On-prem

Factory for private capacity.

Sensitive teams can run dedicated capacity in their office with managed hardware and clear custody conditions.

Security FAQ

Questions legal and CTO ask first.

Does Cardumen upload my repo to the cloud?

Not by default. Cardumen is local-first: rules, memory, skills, hooks and verify live in your repo and machine.

How does it validate the license?

The license is cached locally and validated offline with an Ed25519 signature. There is no fail-open path when the signature cannot be verified.

What is encrypted?

The decision engine and sensitive harness artifacts are decrypted per session with an active license.

Is there an on-prem option?

Yes. Factory On-Prem installs dedicated private capacity for teams with NDAs and sensitive data.

Next step

If security is the blocker, let us talk about deployment mode.

CLI Core, Local and Factory cover different privacy levels. The route depends on data, hardware and compliance.