Download
Security & Trust

Your code stays yours.
We orchestrate, we don’t store.

PromptOps launches and coordinates the command-line AI agents installed on your computer. Prompts and code go straight to the provider you choose, with your own account. This page explains what passes through our servers, where it lives and how we protect it.

Last updated: 26 September 2026

In short

Code never passes through our servers

Agents run on your machine. Source code, diffs and project context travel from your computer to the AI provider you picked. We keep no copy.

AI providers with your own account

Claude Code, Codex, Gemini and the others use your subscription or your key. The data agreement is between you and the provider, and you pick it per session.

Account data in the European Union

Accounts, prompt library and session metadata live on AWS in Milan (eu-south-1). Transactional email leaves from the same region.

Signed updates

Every app release is signed with a key kept offline. The app verifies the signature before installing any update.

Data flows

What goes where

For each kind of data, the path it actually takes. Optional features stay off until you turn them on.

Prompts, code and project context

To your provider

They enter the agent’s terminal on your computer. The provider’s CLI sends them to its servers with your credentials. PromptOps neither intercepts nor stores them.

Project index and semantic search

Local only

Code embeddings are computed on-device and saved in the workspace’s .promptops folder, excluded from git. Nothing leaves the machine.

Terminal output

Local only

Each session’s buffer stays on local disk, encrypted at rest, so sessions can be restored after a restart.

Session metadata

To PromptOps

Name, status, provider, prompt count and the folder path (encrypted) sync with the backend for the multi-device session list and usage metrics.

Prompt library

To PromptOps

Prompts you choose to save in the library live on the backend, in clear, because they are meant to be reused and shared with your team. You decide what goes there.

Voice dictation

Optional

By default transcription happens on-device. The cloud engine is opt-in with a notice; audio is sent to the chosen service and the temporary file deleted right after.

Prompt generator and speed test

Optional

The only features where text passes from our backend to an AI provider. The text is what you type into the feature, never your code.

Mobile remote control

Optional

The relay forwards terminal input and output between phone and desktop over TLS. It keeps no content: logs only hold technical connection events.

Architecture

The components and where they run

Five parts. Only three touch our servers, and none of them receives your code.

ComponentWhat it doesWhere it runsData it sees
Desktop appLaunches CLIs, manages sessions, sub-agents, git, editorYour computer (macOS, Windows, Linux)Everything, locally
Backend APIAccounts, licences, prompt library, session sync, metrics, plugin registry, updatesAWS eu-south-1 (Milan)Account data, session metadata, library prompts
RealtimePresence and in-app notificationsAWS eu-south-1 (Milan)User ID, status, usage hours
Mobile relayBridge between mobile app and desktopAWS eu-south-1 (Milan)Terminal stream in transit, not stored
WebsiteDocs, downloads, newsCDNAnalytics with consent

Sub-processors

Who touches the data, and when

Complete list of third parties. The AI providers you choose for agents are not our sub-processors: that relationship is yours.

ServicePurposeWhenDataRegion
Amazon Web ServicesBackend hosting, database, file storage, transactional emailAlwaysAccount data, session metadata, avatars and attachments, emailEU, Milan (eu-south-1)
AI providers you choose (Anthropic, OpenAI, Google, xAI, etc.)Generation through their CLIWhen you launch an agentPrompts, context, codePer your contract with the provider
GroqCloud voice transcriptionOnly if you enable cloud voiceDictation audioUSA
OpenAI, Anthropic (API)Prompt generator, speed testOnly when you use these featuresText entered in the featureUSA
Google, Apple, GitHub, LinkedIn, FacebookSocial sign-inOnly if you choose social loginEmail, name, profile IDUSA
Papertrail, SlackTechnical logs and internal operational alertsAlwaysApplication logs: IP, user agent, errors. Never prompt contentUSA
Google AnalyticsWebsite statisticsOnly with cookie consentPseudonymous navigation eventsUSA

Transfers to the United States are covered by Standard Contractual Clauses. Any change to this list is announced to customers with an active contract 30 days in advance.

Security measures

How we protect what passes through us

The measures cover the installed app, transport and the backend.

On your device

  • Access tokens and provider keys in the system keychain or encrypted at rest with the operating system key.
  • Terminal buffers and pending prompts encrypted at rest.
  • SSH credentials in AES-256-GCM.
  • Project .promptops folder excluded from git; embeddings computed locally.
  • Agents run with your user’s permissions, inside the workspace folder you opened.

In transit

  • TLS 1.2 or higher on every connection to backend, realtime and relay.
  • Updates signed with an offline key; the app rejects unsigned or tampered packages.
  • No prompts in relay or backend logs.

On the backend

  • Hosted in the European Union, AWS eu-south-1, with encrypted daily backups.
  • Every endpoint is bound to the authenticated user: one account’s data is unreachable from another.
  • Folder paths encrypted in the database; passwords hashed with bcrypt.
  • Service secrets in environment variables, never in code; development and production environments separated.
  • Application logs without prompt content.

Plugins and supply chain

  • Plugins declare the permissions they use and run in a sandbox.
  • Every plugin in the official catalog passes a static scanner and a review before publication.
  • Plugin code is public on GitHub; you can read it before installing.
  • Reproducible CI builds, dependencies updated at every release.

Controls

What you get to decide

What is available today and what we are building for teams with governance requirements.

Available

Provider per session

Choose which agent each session uses. No provider is called behind your back.

Available

Local voice

On-device transcription is the default. The cloud engine only turns on with explicit consent.

Available

Opt-in auto-approval

Modes that skip confirmations are off by default and enabled per session, with a warning.

Available

Plugins from the reviewed catalog only

The app installs plugins from the official registry. Permissions are visible before installation.

Available

Export and delete

Export your data and delete your account yourself from settings.

In development

Organization policies

An admin will be able to switch off, for the whole team, server-side AI features, cloud voice, non-allowlisted plugins, auto-approval and remote sessions.

In development

Exportable audit log

Sign-ins, settings and policy changes exportable to your SIEM.

In development

SAML SSO and SCIM

Sign-in with your corporate identity provider and automatic user provisioning.

Incidents

What happens if something goes wrong

A process with defined timings, designed for customers who in turn must report to regulators.

Within 24 hours

Notification to affected customers for every confirmed incident touching the confidentiality, integrity or availability of their data. Includes what happened, which data, what we are doing.

Within 72 hours

Update with final scope, cause and containment measures applied.

Within 30 days

Final report with root cause, impact and corrective actions. Where personal data is involved, notification to the supervisory authority follows GDPR deadlines.

Reporting a vulnerability

If you find a security issue, write to us. We reply within three business days and keep the reporter updated until closure. Good-faith research that does not access other users’ data or degrade the service will not face legal action from us.

security@shellonback.com

Compliance

Regulations and documents

What we can sign today and what we are preparing.

GDPR

Available

Data processing agreement with Standard Contractual Clauses on request. Sub-processor list on this page. Self-service export and deletion.

AI Act

Available

PromptOps orchestrates third-party models and does not supply them. Dedicated notice on AI providers, output limits and auto-approval modes.

DORA for financial entities

Available

Contractual addendum with the Article 30 clauses, register-of-information data sheet and a 24-hour incident notification commitment. Available on request for banks, insurers and intermediaries.

Third-party penetration test

In development

Annual independent test with a summary shareable with customers.

SOC 2 Type II / ISO 27001

In development

Certification path under evaluation. Ask us for the current status.

FAQ

The questions security leads ask us

Is my source code stored on your servers?

No. Agents run on your computer and talk directly to the AI provider you chose. The backend only receives session metadata and the prompts you decide to save in the library.

Which AI providers see my prompts?

Only the one you pick per session, with your account. PromptOps adds no intermediate provider. The only exceptions, all optional, are cloud voice, the prompt generator and the speed test.

Where is my account data hosted?

On AWS in the eu-south-1 region, Milan. Backups and transactional email stay in the same region.

Can I get a DPA or a DORA addendum?

Yes. Write to the security team stating your type of organisation: you will receive the data processing agreement and, for financial entities, the DORA addendum with the register-of-information data sheet.

How are updates distributed?

Every release is signed with a key that never leaves the build infrastructure. The app verifies the signature before installing. A separate beta channel exists and can be ignored.

What can agents do on my machine?

Anything your user can do inside the workspace folder: read, write, run commands. That is why auto-approval modes are opt-in and per session.

Need a questionnaire filled in?

We answer vendor security questionnaires, provide DPAs and DORA addenda, and set up a technical call with the people who wrote the code.

Contact the security team
Shellonback

Preferenze cookie

Scegli quali categorie di cookie accettare. I cookie tecnici e funzionali sono sempre attivi.

Per maggiori informazioni, consulta la nostra Cookie Policy e la Privacy Policy.

Cookie di profilazione

Utilizzati per creare profili relativi all'utente e inviare messaggi promozionali in linea con le preferenze espresse.

Cookie analitici

Ci permettono di capire come gli utenti navigano il sito per migliorare l'esperienza e i contenuti.

Cookie tecnici

Sempre attivo

Necessari per il funzionamento del sito. Non possono essere disattivati.

Cookie funzionali

Sempre attivo

Consentono funzionalità avanzate come la memorizzazione delle preferenze di navigazione.