Skip to content

For procurement & security

This page is built to be handed to your IT, security, and procurement reviewers before the pilot starts, so day 0 isn’t spent waiting on approvals. Everything here links to the full detail; this is the one-page version a reviewer can clear.

Data Workers installs as agents inside your engineers’ coding tools, running on your machines, holding credentials on your machines, calling your data systems directly. We are not a SaaS that ingests your data: no credentials, warehouse data, query results, or PII touch Data Workers servers. Model inference goes from your environment to your own model provider on your own key — never through us. The pilot is free, 90 days, with exit terms fixed in the agreement before anything installs.

ItemDetail
Node.js 20+On each participating engineer’s machine
A supported coding agentClaude Code, Cursor, Codex CLI, or OpenCode (others work too)
npm registry accessregistry.npmjs.org reachable (Artifactory/Nexus proxies are fine — flag it at kickoff so the private packages get mirrored)
The customer npm tokenIssued by us at signature: scoped, read-only, expires on the pilot end date
Read credentialsService accounts for in-scope systems, created per the least-privilege grants — read-only; write is a separate, later, opt-in decision
Model provider keyYour own (Anthropic, OpenAI, Bedrock, Azure, or a local/open-weight model)
MDM-managed machinesSupported — tell us in advance and we’ll provide the managed configuration

Nothing requires inbound network access, browser plugins, or software outside the engineers’ existing toolchain.

  • Local installs (the default): nothing. Telemetry is off.
  • Pilot installs run with usage telemetry on (it’s in the agreement, and it’s how your usage reports get made): tool-call counts by name/status/client, SHA-256-hashed arguments, install-funnel events, IP truncated to /24, 13-month retention. Never: query results, schemas, credentials, payload bodies, PII. Opt out any time; honored in minutes; the pilot continues. Full detail: Usage data & telemetry.
  • Model traffic: your environment → your model provider, on your key and your DPA with that provider.

Read agents are structurally unable to mutate your systems. Write behavior requires a separate, explicitly enabled, write-scoped credential; every governed write produces a receipt (what changed, proposed by which agent, approved by whom, when); irreversible actions always require human approval — enforced in code, not configuration. Audit trails are hash-chained and exportable. Detail: How your data is handled.

SOC 2 Type II — in progress. We are pre-certification and won’t imply otherwise. Written security policies, a controls inventory, and an incident-response runbook exist and our audit-readiness program is active — ask us where it stands and we’ll walk your reviewers through it: Compliance status · [email protected].

The data-protection paperwork travels with the pilot agreement: ask [email protected] for the current DPA and subprocessor list any time — before signature is the right time. Model traffic never touches us, so your existing DPA with your model provider governs it. Data-residency requirements (where the usage counters and any hosted workspace live) are scoped honestly on the Enterprise deployment track rather than promised generically here.

90 days · full Scale surface · free, no card · telemetry consent as above · evaluation license expires on the end date · uninstall-on-exit with the Apache-2.0 open-source core explicitly exempt (yours forever) · your data never held by us, so there’s nothing to return · hosted residue purged on a 90-day clock. The full exit procedure is public: Ending a pilot.

SSO/SAML, SCIM, dedicated VPC or bring-your-own-cloud, PrivateLink / Private Service Connect, on-prem and air-gapped deployment are available and set up with us — scope them at signature so provisioning starts immediately: Enterprise deployment track.


Cleared everything? Then day 0 is a one-hour call: Your pilot: day 0 to live.