← BackEnterprise
Defender for teams that can't compromise on security.
No data leaves your network
Every user prompt, every file read by the agent, every command output — all tokenized locally before any API call. No third-party proxy. No telemetry. No analytics servers. Every line of source code is open for audit.
Self-hosted provider registry
Defender ships with a bundled provider catalog. No dependency on models.dev or any external service. Ship with your organization's approved model list. Add or remove providers as your policy requires. The registry is a single JSON file — audit it, version it, deploy it.
Air-gapped deployment
Works entirely offline. Connect to local models via Ollama, LM Studio, or vLLM. No internet connection required for full functionality. All privacy operations happen in-process — no daemon, no service, no network listener.
Custom PII patterns
Add organization-specific detection patterns with custom regex. Identify internal identifiers, project codes, customer IDs, or any proprietary format that must stay within your perimeter. Patterns are configured once and enforced globally across all users.
BYOK — Bring your own keys
Use any AI provider. OpenAI, Anthropic, Google, AWS Bedrock, Azure — 165+ supported. No vendor lock-in. No Defender subscription. Your API keys, your usage, your billing.
Compliance ready
SOC 2, HIPAA, PCI-DSS — Defender's architecture supports compliance requirements by ensuring sensitive data never leaves your controlled environment. Tokenization happens before transmission. Vaults are in-memory only. No persistent storage of credentials.