Security
Zero egress, by architecture.
Written for a security reviewer and a procurement officer. What never leaves your machine, the single network interaction that does, and a license chain that is deliberately boring.
- Your source code. Never uploaded, never sampled, never embedded remotely.
- Your prompts and chat history.
- The model's inputs and outputs.
- Telemetry: there is none. The application contains no analytics, crash-reporting, or usage-phoning code path.
The single network interaction in the product is licensing (below). It carries no code, no prompts, and no usage data, and the product keeps working without it for the grace period.
The one network touch, fully disclosed:
- Subscription entitlements are Ed25519-signed tokens issued by the TypeWright licensing server.
- Verification happens locally against a public key shipped in the app — the server is never in the completion, chat, or refactor path.
- Offline grace: an installed entitlement keeps the product fully functional offline for the grace window; renewal is a signed-token refresh, not a session. The 14-day trial is issued the same way.
- Air-gapped / site-license option: entitlements can be issued and transferred out-of-band (file-based) for environments with no outbound connectivity at all. Talk to us about a site license →
| Component | License | Note |
|---|---|---|
| Editor base | MIT (Code-OSS) | Thin fork; Microsoft-proprietary components and Marketplace are not used |
| Model base | Apache-2.0 (Qwen2.5-Coder) | Open weights; fine-tuned derivative also Apache-2.0-clean |
| Fine-tuned model (nimble-ts-coder) | Apache-2.0 | You possess the weights on disk |
| TypeWright application & licensing | Commercial (subscription) | — |
The chain is deliberately boring: permissive open-source at the base, a documented fine-tune in the middle, a commercial license on top. Nothing in the stack can be revoked upstream.
This site is statically generated and loads no third-party scripts or fonts. We count aggregate first-party page views without visitor identifiers. Admin sign-in uses an essential session cookie. Invitation requests are stored securely and sent through Resend. See our privacy policy for the full details.
The same picture the product is built around. See the full product →