Credentials scoped below any developer and revoked at teardown, zero source code retention, and an audit trail for every action. Security your team can verify, not take on trust.
Every session gets its own credentials: a GitHub token limited to the permissions and repos you allowed and an API token scoped to that session, all revoked when the sandbox is torn down. GitHub enforces the scopes at the token mint, so nothing in the sandbox can exceed them.
Permissions minted per session, enforced by GitHub
Zero source code retention: your code exists only inside a session’s sandbox and is deleted when the sandbox is torn down. Every agent action is logged and auditable, so security is something your team can verify, not take on trust.
The transcript outlives the sandbox, the code does not
Ellipsis is SOC 2 Type 1 certified, with Type 2 in progress. Controls cover security, availability, and confidentiality. Request our report at team@ellipsis.dev.
Security, availability, and confidentiality controls
Everything the platform enforces for you, so governance is not each developer’s job.
Minted per session, narrowed to the repos and permissions in the agent config, enforced by GitHub.
Every sandbox credential expires or is revoked when the sandbox is torn down.
Stored values inject into allowed sandboxes and can never be read back out.
Every session is tied to a person, an API key, or a parent session.
Every turn, tool call, and diff is recorded and searchable, with retention you control.
Account, installation, and billing events on record.
Code exists only inside a session sandbox and is deleted when the sandbox is torn down.
Certified, with Type 2 in progress. Request the report at team@ellipsis.dev.
Deploy into your AWS account so credentials, code, and LLM calls never leave it.
Route tokens through your own Anthropic key or your AWS Bedrock account.