Security and data handling
Every environment fully isolated, secrets injected at run time and kept out of your snapshots, and no training on your code.
Isolation
Each environment is fully isolated from every other, and nothing is shared with another customer. The workload exists to run code a language model just wrote, so the boundary has to hold against code nobody reviewed.
We test that boundary by attacking it rather than asserting it. Runs can run behind an outbound allow-list, or with no network at all, and nothing in one environment can address another.
Secrets
Secrets are stored once and injected at run time. They are never written into a snapshot unless you explicitly force it, never passed on a command line, and never part of a snapshot's hash.
This matters more than it sounds: a secret baked into a snapshot is shared with every fork of that snapshot, forever, including forks taken by someone else in your organisation.
Your code and your outputs
Your repo is cloned and snapshotted. Snapshots are deleted when you delete them, and whatever a run changes is discarded unless you keep it.
Promigence does not train on your code, your agent's outputs or your test results. Failed runs are kept for replay for 7 days by default, and the window is set per plan.
Your own cloud account
If your data cannot leave your boundary, talk to us about running Promigence in your own cloud account.
Compliance, stated honestly
Promigence does not hold a SOC 2 report today. We would rather say so than imply otherwise; until we do, we answer security reviews directly.
An environment holds a repo snapshot, the agent's outputs and your verifier code. It does not hold model weights, personal data or production systems. For evals on public repos this is not a compliance question at all.
Reporting a vulnerability
Email support@promigence.ai with "security" in the subject. We will acknowledge within one business day, keep you updated while we fix it, and credit you publicly unless you would rather we did not. We will not threaten anyone who reports a problem in good faith.
Related
Run your own workload on it, free
Send a repo and the command you run against it, whatever that is: an eval suite, an RL rollout, a CI job, a queue of coding tasks. We build the environment once, run it a thousand times, and send back the timings, the failures and an exact price. Free, once, on your real workload.
- 1,000 runs of your own command, on your own repo
- What each one cost in wall clock, and anything that failed
- Whether a failure was your code or the environment
- An exact price for your real volume
Not ready to hand over a repo? Read the quickstart or check the numbers first.