Security
Where the code goes: nowhere.
ByteBell runs inside your network. Here is what that means, line by line, and what we put in the contract.
Runs on your servers, your VPC, or air-gapped.
Binds to localhost by default.
No-egress mode blocks every outbound connection and fails closed.
Every attempted call is logged.
Models stay yours.
Resident open-weight models on your GPUs, or an endpoint you already approved. We never train on your code and never see it.
Storage is one directory on your disk.
Delete it and nothing remains.
Signed install.
Signed bundle, checksums published, no curl-pipe-to-shell in the enterprise edition.
The engine is readable.
Source is available for review under NDA or on GitHub. Read the engine.
SOC 2 Type 1: in progress.
We will publish the date here once the audit is scheduled.
Pilots take no copy.
We index on your machine or a machine you provision. We do not take a copy.
Send us your security questionnaire.
Or watch the audit log show zero outbound calls on a five-repository pilot on your machine.