PromptOps launches and coordinates the command-line AI agents installed on your computer. Prompts and code go straight to the provider you choose, with your own account. This page explains what passes through our servers, where it lives and how we protect it.
Last updated: 26 September 2026
In short
Agents run on your machine. Source code, diffs and project context travel from your computer to the AI provider you picked. We keep no copy.
Claude Code, Codex, Gemini and the others use your subscription or your key. The data agreement is between you and the provider, and you pick it per session.
Accounts, prompt library and session metadata live on AWS in Milan (eu-south-1). Transactional email leaves from the same region.
Every app release is signed with a key kept offline. The app verifies the signature before installing any update.
Data flows
For each kind of data, the path it actually takes. Optional features stay off until you turn them on.
They enter the agent’s terminal on your computer. The provider’s CLI sends them to its servers with your credentials. PromptOps neither intercepts nor stores them.
Code embeddings are computed on-device and saved in the workspace’s .promptops folder, excluded from git. Nothing leaves the machine.
Each session’s buffer stays on local disk, encrypted at rest, so sessions can be restored after a restart.
Name, status, provider, prompt count and the folder path (encrypted) sync with the backend for the multi-device session list and usage metrics.
Prompts you choose to save in the library live on the backend, in clear, because they are meant to be reused and shared with your team. You decide what goes there.
By default transcription happens on-device. The cloud engine is opt-in with a notice; audio is sent to the chosen service and the temporary file deleted right after.
The only features where text passes from our backend to an AI provider. The text is what you type into the feature, never your code.
The relay forwards terminal input and output between phone and desktop over TLS. It keeps no content: logs only hold technical connection events.
Architecture
Five parts. Only three touch our servers, and none of them receives your code.
| Component | What it does | Where it runs | Data it sees |
|---|---|---|---|
| Desktop app | Launches CLIs, manages sessions, sub-agents, git, editor | Your computer (macOS, Windows, Linux) | Everything, locally |
| Backend API | Accounts, licences, prompt library, session sync, metrics, plugin registry, updates | AWS eu-south-1 (Milan) | Account data, session metadata, library prompts |
| Realtime | Presence and in-app notifications | AWS eu-south-1 (Milan) | User ID, status, usage hours |
| Mobile relay | Bridge between mobile app and desktop | AWS eu-south-1 (Milan) | Terminal stream in transit, not stored |
| Website | Docs, downloads, news | CDN | Analytics with consent |
Sub-processors
Complete list of third parties. The AI providers you choose for agents are not our sub-processors: that relationship is yours.
| Service | Purpose | When | Data | Region |
|---|---|---|---|---|
| Amazon Web Services | Backend hosting, database, file storage, transactional email | Always | Account data, session metadata, avatars and attachments, email | EU, Milan (eu-south-1) |
| AI providers you choose (Anthropic, OpenAI, Google, xAI, etc.) | Generation through their CLI | When you launch an agent | Prompts, context, code | Per your contract with the provider |
| Groq | Cloud voice transcription | Only if you enable cloud voice | Dictation audio | USA |
| OpenAI, Anthropic (API) | Prompt generator, speed test | Only when you use these features | Text entered in the feature | USA |
| Google, Apple, GitHub, LinkedIn, Facebook | Social sign-in | Only if you choose social login | Email, name, profile ID | USA |
| Papertrail, Slack | Technical logs and internal operational alerts | Always | Application logs: IP, user agent, errors. Never prompt content | USA |
| Google Analytics | Website statistics | Only with cookie consent | Pseudonymous navigation events | USA |
Transfers to the United States are covered by Standard Contractual Clauses. Any change to this list is announced to customers with an active contract 30 days in advance.
Security measures
The measures cover the installed app, transport and the backend.
Controls
What is available today and what we are building for teams with governance requirements.
Choose which agent each session uses. No provider is called behind your back.
On-device transcription is the default. The cloud engine only turns on with explicit consent.
Modes that skip confirmations are off by default and enabled per session, with a warning.
The app installs plugins from the official registry. Permissions are visible before installation.
Export your data and delete your account yourself from settings.
An admin will be able to switch off, for the whole team, server-side AI features, cloud voice, non-allowlisted plugins, auto-approval and remote sessions.
Sign-ins, settings and policy changes exportable to your SIEM.
Sign-in with your corporate identity provider and automatic user provisioning.
Incidents
A process with defined timings, designed for customers who in turn must report to regulators.
Notification to affected customers for every confirmed incident touching the confidentiality, integrity or availability of their data. Includes what happened, which data, what we are doing.
Update with final scope, cause and containment measures applied.
Final report with root cause, impact and corrective actions. Where personal data is involved, notification to the supervisory authority follows GDPR deadlines.
If you find a security issue, write to us. We reply within three business days and keep the reporter updated until closure. Good-faith research that does not access other users’ data or degrade the service will not face legal action from us.
security@shellonback.comCompliance
What we can sign today and what we are preparing.
Data processing agreement with Standard Contractual Clauses on request. Sub-processor list on this page. Self-service export and deletion.
PromptOps orchestrates third-party models and does not supply them. Dedicated notice on AI providers, output limits and auto-approval modes.
Contractual addendum with the Article 30 clauses, register-of-information data sheet and a 24-hour incident notification commitment. Available on request for banks, insurers and intermediaries.
Annual independent test with a summary shareable with customers.
Certification path under evaluation. Ask us for the current status.
FAQ
No. Agents run on your computer and talk directly to the AI provider you chose. The backend only receives session metadata and the prompts you decide to save in the library.
Only the one you pick per session, with your account. PromptOps adds no intermediate provider. The only exceptions, all optional, are cloud voice, the prompt generator and the speed test.
On AWS in the eu-south-1 region, Milan. Backups and transactional email stay in the same region.
Yes. Write to the security team stating your type of organisation: you will receive the data processing agreement and, for financial entities, the DORA addendum with the register-of-information data sheet.
Every release is signed with a key that never leaves the build infrastructure. The app verifies the signature before installing. A separate beta channel exists and can be ignored.
Anything your user can do inside the workspace folder: read, write, run commands. That is why auto-approval modes are opt-in and per session.
We answer vendor security questionnaires, provide DPAs and DORA addenda, and set up a technical call with the people who wrote the code.
Contact the security teamScegli quali categorie di cookie accettare. I cookie tecnici e funzionali sono sempre attivi.
Per maggiori informazioni, consulta la nostra Cookie Policy e la Privacy Policy.
Utilizzati per creare profili relativi all'utente e inviare messaggi promozionali in linea con le preferenze espresse.
Ci permettono di capire come gli utenti navigano il sito per migliorare l'esperienza e i contenuti.
Necessari per il funzionamento del sito. Non possono essere disattivati.
Consentono funzionalità avanzate come la memorizzazione delle preferenze di navigazione.