Isolated agent work
Separate workspaces and Git worktrees reduce accidental overlap between concurrent coding tasks.
Codius security
Codius separates the desktop tools that operate on your repository from the model providers that answer inference requests. Its controls are designed around least privilege, organization isolation, and minimal content retention.
Controls
These statements describe the current application behavior. Codius does not claim certifications or compliance attestations it has not earned.
Separate workspaces and Git worktrees reduce accidental overlap between concurrent coding tasks.
Organization keys grant only selected model-read, inference, and usage-read scopes. They never carry billing or administrator permissions.
Codius API-key plaintext is presented only when created. The service stores a verifier rather than the reusable secret.
Prompts, outputs, tool arguments, reasoning, and API keys are not written to Codius application logs, analytics, traces, or error-monitoring events.
Membership, API keys, usage, billing, and administrative actions are checked against organization ownership and permissions.
Public model identifiers remain stable while model-provider credentials, routing, and economics stay inside server infrastructure.
Data flow
Responsible reporting
Do not include active credentials or sensitive customer data in an initial report.
Send a concise description, affected surface, reproduction steps, and potential impact to [email protected]. Reports are reviewed before public discussion.
The Codius App repository is public, so local behavior and integration boundaries can be reviewed directly.