Security
Runs in your environment. Here's exactly what it does there.
Polyglot is self-hosted: the agent, the gateway and their logs run on your infrastructure, and none of your code, prompts or model output comes to us. This page lists every network connection it makes, what it stores, how we build and release it, and where we stand on certification. Each item says whether it works today or is planned.
What leaves your network
The complete list of outbound connections. Run the CLI against a local model with web search off, and the only connection that leaves the network is the npm version check.
Polyglot CLI
The model endpoint you configure
The conversation. With a local model it never leaves the machine.
The search backend, only when the agent searches the web
The search query. DuckDuckGo by default, or your own SearXNG.
Remote MCP servers you add
Whatever the model passes to those tools.
npm registry, at startup
A version check. Nothing about your session.
Polyglot gateway (teams)
Your model servers
The requests your agents send through it.
Your own control plane, if you run one
Activity and audit events, to a server you host.
Our licensing endpoint, only if you turn on automatic license renewal
Your license ID, to fetch a renewed license file. Off by default; without it, you install a new license file yourself. Seat limits are checked offline, against the license file.
Details for the CLI, including every file it writes and every setting that controls it, are in Data handling.
What it stores
How we build it, and how it protects you
- Every npm release is built in CI and published with a signed provenance attestation, so you can verify it came from our repositoryWorking today
- CodeQL security scanning on every change and weekly, and dependency alerts for known vulnerabilitiesWorking today
- Secret scanning of tool output: API keys, tokens and private keys are flagged or redacted before they reach the modelWorking today
- Tool calls are only ever read from the model's own replies: text in a file or web page that looks like a tool call is never run as oneWorking today
- Permission modes: approve every write, command and network call; plan first and approve the plan; or run freely within deny rules you setWorking today
- A software bill of materials (SBOM) with every releasePlanned
- Policies as signed, versioned files, signed with a key you holdPlanned
- Sign-in through your identity provider (OIDC), with SAML and SCIM for EnterprisePlanned
- A sandbox for the commands agents runPlanned
Certification and assurance
Security questionnaires
We'll complete yours, whether it's CAIQ, SIG Lite or your own format, and walk your team through the architecture.
SOC 2 and ISO 27001
Not certified yet. Polyglot runs in your environment and none of your data comes to us, which keeps the scope small. We'll certify when our first customers' procurement requires it: ISO 27001 or SOC 2, whichever they ask for.
Penetration testing
An independent test of the gateway is planned before the governance features are generally available. We'll share the summary.
Reporting a vulnerability
Please use GitHub's private vulnerability reporting rather than a public issue. Reports are acknowledged as quickly as possible; Polyglot is early-stage, so response times are best effort rather than a contractual SLA. The full policy, including what counts as expected behaviour, is in SECURITY.md. For a security review or questionnaire, use the teams page to get in touch.