Your code never leaves your repos.
The scan is read-only. The server is self-hosted in your network. Everything Timo generates is committed to your git. That is not a policy promise — it is how the product is built, and your security team can check it by reading the install PR.
Security as architecture, not paperwork.
Most vendors answer security questions with documents. We answer with a design you can verify: nothing in Timo requires your code to reach us.
The facts, each one checkable
- The scan is read-only — it writes nothing to your repo
- The server runs in your infrastructure. It speaks MCP; there is no Timo cloud your code passes through
- Every artifact is committed to your git — cancel anytime, keep all of it
- Thin hooks in each tool, one vendor-independent gate in CI
- Runs air-gapped today, on files and folders alone — not a roadmap item
- Zero secrets leaked across everything we've documented — 2,265 tables, 1,314 screens, 34 modules
- Your code, your systems, your IP
Everything runs inside your network.
One self-hosted server holds the brains — memory, cited docs, scan, blast radius, scoreboard. Thin hooks connect it to each coding tool. One gate sits in CI. Your code stays where it already lives: in your repos.
The model runs where your compliance says it runs.
Timo is neutral across model vendors. You point it at the backend your rules require — same product either way. Model calls go from your infrastructure to your chosen backend; we are never in the path.
Anthropic API
Direct API access. The default for teams already on Claude Code.
AWS Bedrock
Models inside your existing AWS account, under your existing agreements.
Google Vertex
Same on GCP — your project, your region, your controls.
On-prem endpoints
Self-hosted models for teams whose code and prompts can never leave the building.
What about certifications?
Here is the straight answer, because you were going to ask.
We’re a young company, and we won’t wave certificates we don’t have.
Instead, we designed Timo so you don’t have to trust our infrastructure at all — your code never reaches it. The server runs in your network. The scan is read-only. Every artifact lands in your git.
Your security team can verify that claim themselves, by reading the install PR. Everything Timo does arrives as files in your git — reviewable, diffable, removable.
Built for the strictest network you have.
Banking, healthcare, government — teams whose code cannot touch a vendor cloud run Timo the same way everyone else does, just further inside.
On-prem runner
The Timo server on your own hardware, behind your own firewall, pointed at an on-prem model endpoint.
Air-gapped install
Timo works on files and folders alone. No internet required — running today, not a roadmap item.
Private rule-packs
Your standards, blueprints, and review rules stay yours — versioned in your git, never shared or pooled.
All three ship with the Enterprise tier — see pricing. Have a setup we haven’t named? Talk to us— the answer is usually yes, and we’ll tell you plainly when it’s no.
The questions your security team will ask.
Short answers here. Longer ones from the founders, directly.
What leaves our network?
Where does the model run?
What data do you retain?
Can we review what gets installed?
Start with the part that touches nothing.
The Agent-Readiness Scan is read-only and takes five minutes. No workspace, no sales call, nothing written to your repo.