Security & Trust

Share the session. Keep the control.

Your whole team can work in one live AI session without giving up your source, your secrets, or your model traffic. Here is where your code lives, how a shared session stays safe, and the controls your security team will ask for.

A drive is your team's isolated workspace. Everything below describes how one drive keeps your code, your secrets, and your sessions yours.
Your own git
Work pushes to your own repositories as ordinary git commits. Your source of record never moves to us, so you can walk away with everything at any time.
Your own keys
Bring your own model keys. Usage is billed by your provider, with no markup from us.
Never trained on
We never use the contents of your drives to train a model, and we never sell your data.

Many people, one agent, and nothing leaks between teams.

Multiplayer does not mean a free-for-all over your code. Four things hold.

01 · sealed

Every drive is its own workspace.

A drive is isolated. One team's drive cannot see, reach, or discover another's. Your code, environment, and sessions stay inside it.

02 · attributable

Verified identity on every action.

Every prompt and edit is tied to a verified identity that cannot be spoofed or impersonated. No one can act as a teammate they are not, so you get an attributable record of who did what.

03 · scoped

Access is set per session.

A session is private to you, shared with named teammates, or open to the drive. People access only the sessions they are granted, and you open a session up only when you are ready.

04 · contained

No master key to steal.

Credentials are scoped to a single drive. There is no global secret, and a problem in one drive cannot reach another.

Your data

What we store: only what is needed to run your drives and bill your usage. Your code, your prompts, your sessions, and your keys are yours. We never read your code to train a model, and we never sell your data. Everything is encrypted in transit and at rest.

When you delete a drive or close your account, the workspace is permanently deleted within 30 days. Deletion covers all copies, including archives. Thirty days is the outer bound, not a holding period, and Enterprise customers can request written confirmation.

Where your model traffic goes is your choice. Use the included models, point us at your own provider keys, or, on Enterprise, route every model call through Amazon Bedrock in your own AWS account. With your own provider keys, retention is governed by that provider's policy and any zero-retention terms you hold with them. With Bedrock, calls run in the AWS region you invoke and never pass through a shared gateway. AWS does not store your prompts or completions, does not use them to train models, and does not share them with the model providers. We never train on your code on any path.

The controls your security team will ask for.

All plansEnterprise
Access & identity
Per-session access controlYesYes
Role-based access: who can create drives, who uses which models, usage limitsYesStronger, org-wide
Verified-identity audit trailYesYes
Single sign-on (SSO / SAML)Not includedYes
SCIM provisioningNot includedYes
Data & deployment
Encrypted in transit and at restYesYes
Never used to train modelsYesYes
Permanent deletion within 30 days, all copiesYesYes, written confirmation on request
Run in your own environmentNot includedYes
Models through Amazon Bedrock in your own AWS accountNot includedYes
Assurance
HIPAA and signed BAANot includedOn request
Independent penetration testingOn requestOn request
For your security team

What your reviewer can ask for.

You do not have to start cold. Email us for a security review, a completed vendor security questionnaire, an independent penetration test, and a BAA for Enterprise deployments. To report a vulnerability, email enterprise@coshell.ai. On Enterprise, breach notification terms are covered in your agreement.

Evaluate it yourself

You do not have to take our word for it.

Launch a free drive and put real code in it. Attach the stock OpenCode CLI to confirm you are never locked to our interface. Push to your own git to confirm you can walk away with everything. When you need a human, email us for a penetration test, written confirmation of deletion, or a BAA.

Start free
Continuity

You can leave with everything, any time.

Your code lives in your own git, so nothing is trapped with us. The stock OpenCode CLI attaches to your drive, so you are never dependent on our interface to reach your work. Keep your repositories, your keys, and your history.

Security, answered

Where does our code live?

Your code lives in your drive while you work and in your own git, which is your source of record. Work pushes to your repositories as ordinary git commits, so you can walk away with everything at any time. Self-host on your own machine and your code stays with you, free; the Enterprise tier adds org-controlled on-prem infrastructure at scale.

Do you train on our code?

No. We never use the contents of your drives to train any model, on any model-routing path, and we never sell your data.

How is our data deleted?

When you delete a drive or close your account, the workspace is permanently deleted within 30 days. Deletion covers all copies, including archives. Thirty days is the outer bound, not a holding period, and Enterprise customers can request written confirmation.

Can we keep model traffic inside our own AWS account?

Yes, on Enterprise. Route every model call through Amazon Bedrock in your own AWS account. Calls run in the AWS region you invoke and never pass through a shared gateway. AWS does not store your prompts or completions, does not use them to train models, and does not share them with the model providers.

Do you support SSO, SCIM, and HIPAA?

Single sign-on with SSO and SAML and SCIM provisioning are available on Enterprise. We will sign a BAA for Enterprise deployments and support HIPAA-aligned configurations using your own environment. Independent penetration testing is available on request.

Put real code in front of your whole team, safely.

Start with a free drive, or talk to us about running Coshell in your own environment with SSO, your own Bedrock, and a BAA.