Your AI Builds in a Locked Room.
You Hold the Key.

Tendril's AI workers build in a safe workspace, never loose on your real files. Genuinely risky moves are blocked before they can happen, and nothing touches your actual project until you approve it. Your code stays on your computer, and what you build is never tracked. That's true on every plan, not just an enterprise tier.

Locked Sandbox
Dangerous Actions Blocked
You Approve Every Change
No Code Tracking

Your Code Never Leaves Your Computer

Tendril runs on your own machine, and your project stays there. When the AI needs to think, it talks straight from your computer to the provider you chose, using your Claude Pro or Max sign-in or your own key. Tendril's servers never see your code, and they never see your keys. Want to back up to GitHub? That's your call, and it goes directly from your machine to GitHub when you say so.

Your ComputerTendril AI workerssupervisedLocked Sandboxdangerous actions blockedyou approve every changepasswords, keys and history kept off-limitsAPI callAI ProviderClaude, GPT, or Geminiyour accountnothing saved until you approve itTENDRIL SERVERSnever see your code

Nothing is saved to your real project until you approve it, and off-limits files like passwords and keys are protected automatically

Safe by Design, Not by Luck

Tendril doesn't just hope the AI behaves. It boxes every AI worker into its own safe workspace, blocks the genuinely dangerous moves on its own, and hands you the final say before anything reaches your project. Here's how that protection stacks up.

Each Worker in Its Own Safe Workspace

Every AI worker builds in a walled-off copy of your project, never your real files. They can't trip over each other, and they can't touch anything they weren't asked to.

  • Workers run isolated, so they never clash
  • Each one only sees the slice of work it was given
  • Your real project stays untouched while they build
  • One worker's mistake can't spill onto the others

You Approve Every Change

Nothing the AI writes is saved to your real project until you look at it and say yes. You're always the last step.

  • Review what changed before it sticks
  • Approve, tweak, or throw it away
  • No surprise edits land behind your back
  • You stay in control from start to finish

Dangerous Actions Blocked Automatically

Genuinely destructive moves are stopped before they can run. You don't have to watch for them.

  • Wipe-everything and force-delete commands blocked
  • Writing outside the assigned job is blocked
  • Secret files like passwords and keys stay off-limits
  • Risky system commands are caught before they run

Spending That Can't Run Away

Tendril keeps an eye on cost so a worker can't quietly burn through your budget. If something's going sideways, it stops.

  • A hard ceiling no run can cross
  • A worker making real progress can earn a little more room
  • Sudden spikes in spending get caught fast
  • You always know what a run is costing

Your Secrets Stay Secret

The files that matter most, like your passwords, keys, and project history, are walled off from the AI by default.

  • Password and key files are never overwritten
  • Your project history is protected
  • Workers can't reach outside their assigned work
  • Off-limits areas are enforced, not just suggested

Catches and Fixes Its Own Mistakes

If a worker gets stuck or goes in circles, Tendril notices, nudges it back on track, and brings you in if it still can't sort itself out.

  • Spots a worker that's looping or stalled
  • Restarts it with guidance on what went wrong
  • Escalates to you when it needs a human
  • Logs what happened so nothing is hidden

See the Guardrails at Work

These are real moments from Tendril keeping a build safe: a risky action getting blocked, and a worker getting flagged the instant it reaches past the job it was given.

A Risky Action, Blocked

Tendril stops a dangerous move before it can run.

Tendril security panel showing a blocked injection attempt

A Worker Caught Out of Bounds

A worker is flagged the moment it reaches outside its assigned work.

Tendril security panel showing a scope violation event
On Every Plan

A Plain-English Record of Everything

Tendril keeps a running log of what the AI did on each project: every file it read, every change it made, every command it ran, and every action that got blocked. It lives on your own computer, you can scroll back through it any time, and you can export it. Nothing is hidden, and nothing is sent anywhere.

Tendril — Security FeedLIVE
All EventsAgent ActionsFile ChangesCommands
TimestampAgentActionTargetSeverity
2026-06-18 00:17:52Master AgentFILE_READsrc/auth/session.tsINFO
2026-06-18 00:18:06Sub-Agent #1FILE_WRITEsrc/auth/jwt.tsINFO
2026-06-18 00:18:20Master AgentPLAN_CREATEDImplement OAuth flowINFO
2026-06-18 00:18:34Sub-Agent #2COMMAND_RUNnpm test -- auth.spec.tsINFO
2026-06-18 00:18:48Master AgentGITHUB_READrepo: org/project@mainINFO
2026-06-18 00:19:02Sub-Agent #3SCOPE_DENIED../../../etc/passwdERROR
2026-06-18 00:19:16Sub-Agent #1FILE_WRITEsrc/components/Button.tsxINFO
2026-06-18 00:19:30Master AgentAPI_CALLanthropic.com — 14 tokensINFO
2026-06-18 00:19:44Sub-Agent #2BASH_BLOCKEDrm -rf / — blocked (sandbox)ERROR
2026-06-18 00:19:58Master AgentGIT_COMMITfeat: add auth middlewareINFO
Saved on your computer, one log per projectExport CSV ›

Your Questions, Answered Straight

How Tendril handles your code, your AI, and your privacy.

No. Tendril's AI workers run on your own computer, and your code stays there. When the AI needs to think, it talks directly from your machine to the provider you picked, using your Claude Pro or Max sign-in or your own key. If you connect a GitHub repository, that goes straight between your machine and GitHub. Tendril never receives your code.

Two ways. First, every AI worker builds inside a locked sandbox, isolated from your real files, and genuinely dangerous actions are blocked automatically, like wipe-everything commands, writing outside its assigned job, or touching secret files such as your passwords and keys. Second, nothing is saved to your real project until you review it and approve it. You're always the final say.

Tendril notices when a worker is looping or stalled, restarts it with guidance on what went wrong, and tries a different approach. If it still can't sort itself out, Tendril brings you in with clear choices: try again, drop that piece, or take it over yourself. Every step is written to the activity log.

We count the tokens your projects use — tied to your account — so we can keep you within your plan's monthly limits and prevent abuse. That is the only thing we measure, and it is never your code. We do not track your keystrokes, your file names, or what you build, and there is no behavioral analytics or telemetry. The detailed activity log of what the AI did stays on your own computer, and you control it.

Still Have Security Questions?

Happy to walk you or your team through exactly how the sandbox works, how approvals work, and how your code and data are handled. Just reach out.

Contact Security Team