Zero Prompt & Code Ingestion Architecture

Security & Trust by Design

Sleev runs as a local gateway on your machine. Your proprietary code, context transforms, provider API keys, and model conversations stay within your security perimeter and never touch our servers.

Zero Model Training Guarantee

Sleev Labs never uses customer prompt contents, source code, completions, or operational telemetry to train, retrain, or fine-tune foundational AI models.

Architectural Trust Boundary

Unlike traditional central AI gateways that man-in-the-middle your code in the cloud, Sleev enforces a strictly isolated, local-first topology.

Traditional Cloud AI Proxies Cloud Man-in-the-Middle
  • All prompts and proprietary source code are sent to a third-party cloud server.
  • Third-party cloud decrypts and inspects all LLM request and response bodies.
  • Provider API keys and sensitive tokens are stored on external vendor infrastructure.
  • Expanded data exfiltration risk and third-party vendor attack surface.
Sleev Local-First Gateway Local Loopback (127.0.0.1)
  • 100% Local Execution: Compaction, transforms, and AST processing happen locally.
  • Direct-to-Provider Wire Path: Requests stream directly from your machine to Anthropic/OpenAI.
  • Zero Secret Ingestion: Provider API keys remain in local memory and are never sent to Sleev.
  • Minimal Telemetry: Control plane only receives high-level token counts and license leases.
Technical & Organizational Safeguards

Comprehensive Enterprise Protection

Zero Code & Prompt Ingestion

Sleev runs as a local daemon on loopback (127.0.0.1). Context optimization, AST transformations, prompt compaction, and session history remain on your machine. Your proprietary code and prompts never touch Sleev servers.

Direct-to-Provider Wire Path

The local gateway forwards completions directly to your configured model providers (Anthropic, OpenAI, or internal VPC endpoints) using your own API credentials. Sleev never sits in the cloud as a man-in-the-middle for prompt payloads.

Strictly Isolated Telemetry

Sleev’s cloud control plane receives only high-level operational metrics: token counts, model names, license verification leases, and billing attribution. No conversation text or source code is ever included in standard telemetry.

Enterprise Identity & Access (SSO / SCIM)

Support enterprise authentication with SAML 2.0 and OIDC Single Sign-On, SCIM directory synchronization, and organization-level role-based access control (RBAC).

Strong Encryption in Transit & at Rest

All control-plane communication is strictly encrypted with TLS 1.3 in transit. Cloud databases and metadata storage on Google Cloud Platform are protected with AES-256 encryption at rest.

Air-Gapped & Offline Licensing

For defense, financial, or high-compliance environments with limited or no internet access, Sleev supports cryptographically verified offline licenses with zero outbound network calls.

Data Flow & Retention Matrix

Clear accountability across every stage of the developer workflow.

Data Category Local Gateway (User Machine) Upstream LLM Provider Sleev Cloud Control Plane
Source Code & Prompts Processed in local memory & SQLite Sent directly over TLS via your API keys Never transmitted, inspected, or stored
Provider API Keys Stored in local client memory / env Forwarded for provider authentication Never sent to or stored on Sleev servers
Token & Savings Telemetry Computed in local gateway Not shared Aggregated numeric counters only
User Identity & SSO Profile Cached local auth token Not shared Name, business email, org role
Diagnostic Logs (Optional) Saved in local debug logs Not shared Client-redacted, voluntary only, 7-day auto-purge

Compliance & Legal Framework

Access our formal compliance documentation, terms, and third-party disclosures.

Responsible Disclosure & Security Inquiries

We take security vulnerabilities seriously. If you discover a potential vulnerability or need assistance with your organization’s vendor security assessment (SIG Lite / CAIQ), our dedicated security team is here to assist.

FAQ

Security & Compliance Questions

Does Sleev store or train models on our source code or prompts?

No. Sleev operates under a strict zero-ingestion architecture. The gateway executes locally on 127.0.0.1, and all prompt rewriting and context optimizations take place on the local machine. Prompts are transmitted directly to your chosen upstream LLM provider. Sleev Labs never receives, stores, logs, or trains AI models on your code or prompt data.

How do provider API keys work with Sleev?

Your provider credentials (e.g. Anthropic, OpenAI, or custom gateway keys) reside on your machine. The local Sleev daemon receives them from your local harness client (Claude Code, OpenCode, Codex, etc.) and forwards them directly to the upstream model provider over HTTPS. Provider keys are never transmitted to or stored in Sleev cloud databases.

What data does Sleev’s cloud control plane collect?

The control plane collects only metadata necessary to verify active software licenses, enforce seat limits, calculate billing attribution, and display aggregate usage dashboards (token counts, request volume, model identifiers, and calculated optimization savings).

Can Sleev run in isolated or air-gapped environments?

Yes. For environments with restricted internet access, Sleev provides an Offline Licensing mode. The gateway verifies an ed25519 cryptographically signed license file completely offline without connecting to the control plane, ensuring zero outbound telemetry.

Do you offer a Data Processing Addendum (DPA) and SOC 2 reports?

Yes. We offer a comprehensive GDPR/CCPA-compliant Data Processing Addendum incorporating EU Standard Contractual Clauses (SCCs) and UK Addendum terms. Our underlying cloud infrastructure is hosted in SOC 2 Type II, ISO 27001, and PCI-DSS certified Google Cloud Platform data centers.