How your data is handled
The 30-second version to give your security team: on local installs, the brain — the agents and all credentials — runs on your machines. We are not a SaaS that ingests your data. No credentials, warehouse passwords, query results, or PII touch Data Workers servers.
The architecture, by surface
Section titled “The architecture, by surface”Terminal agents (all plans). Agents run as local MCP servers inside your coding agent. Credentials are environment variables on your machine; agents call your systems directly. Data path: your machine → your warehouse → your machine. Nothing transits us.
Spellbook console (Scale, research preview). Split-brain design: the UI is a static
page; the brain — agents and credentials — runs locally on localhost:4747 via the local
launcher. The browser talks to your own machine. Same guarantee as the terminal.
Hosted endpoint (Scale/Enterprise, mcp.dataworkers.io). The hosted MCP endpoint
processes requests for workspaces that choose it; what it retains is usage counters only —
documented precisely in Usage data & telemetry.
Dedicated / on-prem (Enterprise). Everything — including hosted surfaces — runs inside your VPC, your cloud account, or your data center, reachable over PrivateLink / Private Service Connect or fully air-gapped. See Onboarding: Enterprise.
Model inference
Section titled “Model inference”You bring your own model key at every plan level. Inference calls go from your environment to your model provider, on your negotiated rate and your data-processing terms with that provider. Inference never routes through Data Workers, and we never add margin to your provider’s rate. Teams with strict requirements run against open-weight or fully local models — the platform doesn’t care which model serves it.
Writes, receipts, and audit
Section titled “Writes, receipts, and audit”- Read agents are structurally unable to mutate your systems.
- Write agents act only with explicitly enabled, write-scoped credentials — and on Enterprise, behind an approval gate.
- Every governed write produces a receipt: what changed, proposed by which agent, approved by whom, when. Audit trails are hash-chained and exportable.
What we never have
Section titled “What we never have”Across every surface: your query results, your schemas’ contents, your credentials, your customers’ PII, your model keys. If a future feature ever needs sight of any of these, it will be opt-in, documented on this page first, and off by default.