Use case

A self-hosted AI coding agent for security sensitive teams

Short answer

Reqursor Development installs on a Linux server you operate. The agent runs in a sandbox that never sees your data directory, your license or your real API keys, and your code goes only to destinations you configure.

Where secrets live

Reqursor Development installs on a Linux server you operate, and your team opens its dashboard in a browser on your network. The secrets you store there are encrypted at rest.

A secret is write only: you can replace or remove it, but never read it back, even as an Owner. Secrets are redacted from logs, live events, the audit log and diagnostics, and they are never part of the daily license check.

What you install, back up and update yourself is covered in Versus hosted AI agents.

What the sandbox can and cannot reach

The agent runs in a sandbox that sees only the project’s working copy. It never sees your data directory, your license or your real API keys.

Model calls go through a local gateway that adds the key on the agent’s behalf. Pushes, pull requests and tracker updates are made by Reqursor Development, not by the agent, so the agent has no credential to push with.

Ticket text is treated as data, never as instructions, and is scanned for prompt injection patterns.

Only destinations you configure

Your code and tickets leave the server for three kinds of destination: the model provider you choose, your git remote and the integrations you connect. You configure all three. Your code goes to the model provider as working context for the ticket being worked on.

The daily license check that Reqursor receives carries eight fields of metadata, with no code, tickets or names. If the license server cannot be reached, work carries on and a banner appears.

Scans, gates and an audit log

A secret scan runs on every ticket, and a genuine secret on a changed line blocks shipping. Protected paths such as environment files, secrets folders and CI workflows refuse the whole commit.

An append-only audit log records every run, decision and settings change. Large or sensitive diffs wait for a person to approve them, and by default Approve & commit and Revert need an Owner or Admin.

Good fit

  • Teams that want the agent’s secrets kept encrypted on their own server, out of the sandbox
  • Security reviews that need a documented data flow, including exactly what the daily license check contains
  • Teams that want an audit trail and approval gates on large or sensitive changes

Not the right fit

  • Self-hosted does not mean no outbound traffic: your code goes to the model provider you choose as working context for each ticket
  • It needs a Linux server you operate with internet access to your model provider and git remote, and it checks its license once a day; an offline license file is available for some licenses, so sites that cannot call out at all should ask first
  • Status today: Onboarding founding customers

Frequently asked questions

Only to places you configure: the model provider you choose, as working context for the ticket, your own git remote and the integrations you switch on. The daily license check that goes to Reqursor carries eight fields of metadata, with no code, tickets or names.

The agent’s sandbox sees only the project working copy. It never sees your data directory, your license or your real API keys, because model calls go through a local gateway that adds the key. Secrets are write only in the dashboard and redacted from logs.

Once a day the install checks its license with Reqursor: an instance ID, a license ID, the version, operating system and architecture, and counts of active users, projects and pipeline runs in the last day. No code, ticket text, repository names, user names or email addresses.

Ticket text is treated as data and scanned for prompt injection patterns. Pushes and pull requests are made by Reqursor Development outside the sandbox, so the agent holds no credential for them. Force-pushes and pushes to protected branches are refused in code.

  • Comparison

    Versus hosted AI agents

    A hosted agent runs on its provider’s machines. Reqursor Development runs on a Linux server you operate, with its secrets on your data volume and spending caps that you set per project.

  • Use case

    Control AI spend

    Every project has spending caps per ticket, per day and per calendar month. When a cap is hit, Autopilot starts nothing new, Run now is blocked and the message names the cap that stopped it.

  • Use case

    Ship with evidence

    Reqursor Development links every acceptance criterion to the lines of the diff that satisfy it, runs your own checks as hard gates, and has a second agent verify the change before a security scan and the ship decision.

See it on your own codebase

See Reqursor Development work through real tickets on a repository like yours, in a 30-minute call with the people who build it.