Your AI Builds in a Locked Room.
You Hold the Key.
Tendril's AI workers build in a safe workspace, never loose on your real files. Genuinely risky moves are blocked before they can happen, and nothing touches your actual project until you approve it. Your code stays on your computer, and what you build is never tracked. That's true on every plan, not just an enterprise tier.
Your Code Never Leaves Your Computer
Tendril runs on your own machine, and your project stays there. When the AI needs to think, it talks straight from your computer to the provider you chose, using your Claude Pro or Max sign-in or your own key. Tendril's servers never see your code, and they never see your keys. Want to back up to GitHub? That's your call, and it goes directly from your machine to GitHub when you say so.
Nothing is saved to your real project until you approve it, and off-limits files like passwords and keys are protected automatically
Safe by Design, Not by Luck
Tendril doesn't just hope the AI behaves. It boxes every AI worker into its own safe workspace, blocks the genuinely dangerous moves on its own, and hands you the final say before anything reaches your project. Here's how that protection stacks up.
Each Worker in Its Own Safe Workspace
Every AI worker builds in a walled-off copy of your project, never your real files. They can't trip over each other, and they can't touch anything they weren't asked to.
- Workers run isolated, so they never clash
- Each one only sees the slice of work it was given
- Your real project stays untouched while they build
- One worker's mistake can't spill onto the others
You Approve Every Change
Nothing the AI writes is saved to your real project until you look at it and say yes. You're always the last step.
- Review what changed before it sticks
- Approve, tweak, or throw it away
- No surprise edits land behind your back
- You stay in control from start to finish
Dangerous Actions Blocked Automatically
Genuinely destructive moves are stopped before they can run. You don't have to watch for them.
- Wipe-everything and force-delete commands blocked
- Writing outside the assigned job is blocked
- Secret files like passwords and keys stay off-limits
- Risky system commands are caught before they run
Spending That Can't Run Away
Tendril keeps an eye on cost so a worker can't quietly burn through your budget. If something's going sideways, it stops.
- A hard ceiling no run can cross
- A worker making real progress can earn a little more room
- Sudden spikes in spending get caught fast
- You always know what a run is costing
Your Secrets Stay Secret
The files that matter most, like your passwords, keys, and project history, are walled off from the AI by default.
- Password and key files are never overwritten
- Your project history is protected
- Workers can't reach outside their assigned work
- Off-limits areas are enforced, not just suggested
Catches and Fixes Its Own Mistakes
If a worker gets stuck or goes in circles, Tendril notices, nudges it back on track, and brings you in if it still can't sort itself out.
- Spots a worker that's looping or stalled
- Restarts it with guidance on what went wrong
- Escalates to you when it needs a human
- Logs what happened so nothing is hidden
See the Guardrails at Work
These are real moments from Tendril keeping a build safe: a risky action getting blocked, and a worker getting flagged the instant it reaches past the job it was given.
A Risky Action, Blocked
Tendril stops a dangerous move before it can run.

A Worker Caught Out of Bounds
A worker is flagged the moment it reaches outside its assigned work.

A Plain-English Record of Everything
Tendril keeps a running log of what the AI did on each project: every file it read, every change it made, every command it ran, and every action that got blocked. It lives on your own computer, you can scroll back through it any time, and you can export it. Nothing is hidden, and nothing is sent anywhere.
| Timestamp | Agent | Action | Target | Severity |
|---|---|---|---|---|
| 2026-06-18 00:17:52 | Master Agent | FILE_READ | src/auth/session.ts | INFO |
| 2026-06-18 00:18:06 | Sub-Agent #1 | FILE_WRITE | src/auth/jwt.ts | INFO |
| 2026-06-18 00:18:20 | Master Agent | PLAN_CREATED | Implement OAuth flow | INFO |
| 2026-06-18 00:18:34 | Sub-Agent #2 | COMMAND_RUN | npm test -- auth.spec.ts | INFO |
| 2026-06-18 00:18:48 | Master Agent | GITHUB_READ | repo: org/project@main | INFO |
| 2026-06-18 00:19:02 | Sub-Agent #3 | SCOPE_DENIED | ../../../etc/passwd | ERROR |
| 2026-06-18 00:19:16 | Sub-Agent #1 | FILE_WRITE | src/components/Button.tsx | INFO |
| 2026-06-18 00:19:30 | Master Agent | API_CALL | anthropic.com — 14 tokens | INFO |
| 2026-06-18 00:19:44 | Sub-Agent #2 | BASH_BLOCKED | rm -rf / — blocked (sandbox) | ERROR |
| 2026-06-18 00:19:58 | Master Agent | GIT_COMMIT | feat: add auth middleware | INFO |
Your Questions, Answered Straight
How Tendril handles your code, your AI, and your privacy.
Does Tendril ever send my code to the cloud?
How does Tendril keep the AI from doing something harmful?
What happens if a worker gets stuck or goes off track?
Does Tendril track me or my usage?
Still Have Security Questions?
Happy to walk you or your team through exactly how the sandbox works, how approvals work, and how your code and data are handled. Just reach out.
Contact Security Team