Built to pass security review.

DevOS runs entirely inside your own environment, never trains on your data, and isolates every workspace. A complete reference for your IT, security and compliance teams.

Data handling

Private by default. Your data stays yours.

How DevOS handles your code and data, and the controls you keep over both.

Nothing leaves on its own

Code, memory and the savings ledger all run on your own hardware and never leave it. Journi receives data only if you opt in, and only ever aggregated statistics and feature requests, never your code.

The control plane is self-hosted too

Connect the org-wide control plane and it runs on your infrastructure as well. Before any opt-in sends a thing, you can review exactly what would leave.

Full control of outgoing calls

Every outbound model call is policy-checked, logged and traceable, so you can see and govern exactly what leaves.

No training on your data

Your code, prompts and activity are never used to train models, or for anything else.

Secret redaction

Secrets are redacted fail-closed, before any write and at any egress boundary.

Keys in your custody

Provider keys live in the OS keychain, never on disk.

Isolation & access
Your data lives where you deploy it, separated by workspace.

Every deployment is dedicated to you, so your code and data never mix with anyone else's. Within it, each repository is its own workspace, letting you control which teams and developers can reach which code and memory.

Dedicated instanceYour deployment is yours alone.
Gate teams and developersGrant access to code and memory per workspace.
Export & delete on demandFull export bundle, and one-click removal.
Governance — Polaris

Govern and monitor across your organisation.

The control plane for IT, security and compliance — set policy once and have it enforced everywhere DevOS runs.

Audit log

A complete, tamper-evident record of policy changes and access decisions.

Policy enforcement *

Control which models can be used and check every session against your active policies.

Budget controls *

Set spending limits, enforced centrally and applied in real time.

Admin recovery

Secure recovery paths for administrators to handle exceptional situations.

Usage export

An evidence pack and usage export ready for finance and compliance teams.

SIEM forwarding

Stream events to Splunk, Sentinel or S3 — in build.

* The level of enforcement depends on the agent host. Some hosts support hard enforcement at the network boundary; others apply advisory checks.

Supply chain

Auditable from the source up.

SBOMs for every ecosystem, dependency gates, and a verified installer — the evidence procurement asks for.

CycloneDX SBOMs

Generated for all three ecosystems — Rust (cargo-cyclonedx), Node (cyclonedx-npm) and C# (dotnet CycloneDX).

Dependency gate

cargo-deny enforces advisory, license and source-registry checks (RUSTSEC) on every build.

Memory-safe by construction

Built in Rust with unsafe code disallowed across the entire codebase, removing a whole class of memory-safety vulnerabilities.

Self-contained components

Core components are built in and statically linked — nothing extra for you to install or patch, and no OpenSSL dependency.

Verified installer

The installer checks every file against a known hash before deploying, and is code-signed.

Pinned toolchain

Build toolchains are pinned to versions that include current security fixes, including CVE-2024-24576.

Deployment

Deploy inside your boundary.

On developer machines, in your own private cloud, or in your data centre, with unattended installer support for Intune, SCCM and MDM.

LocalOn developer machines.
Private cloud / VPCInside your own Azure or AWS — the usual enterprise choice.
On-premisesFully in your own data centre.
Thought leadership
"Working with AI" — how we drive coding agents at Journi. Six habits, one pre-flight checklist.

Most agent failures come down to two habits: guessing when it should check, and calling a task done before proving it. The DevOS Rulebook is our answer.

Download the AI Rulebook

Ready for security review?

We'll send the security pack, SBOMs and deployment guide, and walk your team through the architecture.