← Portfolio
12 Human Enablement Live

CloudCode

Ship code with AI — not your codebase.

Most AI coding tools require shipping your source to a vendor's servers. CloudCode flips that. Point it at a model running inside your perimeter — a local coder on your laptop, a private-cloud endpoint, or an air-gapped box — and your code, prompts and context simply never leave. Public frontier APIs stay available, but strictly opt-in, per project. One agent, any model, at the API level — no compromises.

+ 0 bytes leave the machine with a local model
+ Every provider, one switch — local · private cloud · frontier
+ MCP in both directions — pull tools in, expose itself out
+ Three approval modes · tool-event hooks · resumable sessions

The layer

Act, with Govern in the loop. CloudCode does the work — reads, edits, runs tests, ships diffs — but every action runs behind an approval mode, a hook, and a perimeter you define. Autonomy with the brakes built in.

The problem

Your most valuable code is your most sensitive code. Yet almost every AI coding tool requires sending your source to a vendor’s servers — a non-starter for work that’s under NDA, under regulation, or simply too valuable to hand to someone else’s API. Teams in finance, health, public sector and any business with real trade secrets are forced to choose between the productivity of AI and the confidentiality they’re contractually and legally bound to keep.

What it does

CloudCode is an autonomous coding agent that runs on the models you control. Point it at a model inside your perimeter and your code stays put: on-device with a local coder, inside your private cloud, or fully air-gapped with no outbound network at all. It ships as a portable engine and a live-streaming terminal app that talks to models directly over their native APIs — so the same workflow runs against a frontier cloud model or a 7-billion-parameter coder on your laptop.

It feels immediately familiar to anyone who has used the Claude Code console: the same bordered welcome panel, streaming ⏺ tool calls, live diffs, an approval-mode line and a token/cost status bar. The difference is what sits behind it — here, a local model running entirely on the machine. It’s an early but genuinely working MVP you can run today.

The perimeter

CloudCode draws a hard line and lets you decide what crosses it. Inside your perimeter — code, prompts and context — nothing leaves: on-device models, your private cloud, or air-gapped and offline. Public APIs stay optional — enabled per project when sensitivity allows, switched per task with /model, or disabled entirely with one flag to keep certain repos on-prem only. Your keys, your call.

Companion or standalone

CloudCode runs two ways. Standalone, it’s a complete coding REPL for any developer who needs AI on code that can’t leave the building. As a companion, its embeddable engine is the coding core behind CodeEasy — the same agent loop that powers AutoCode, CodeEasy’s autonomous spec-to-shipped pipeline, called in when a build needs to run privately. One engine, two front doors: a terminal you drive yourself, or a governed pipeline that drives it for you.

Engineered for trust, not just demos

Per-project boundaries pin a repo to local-only models or open it to the cloud. Three approval modes — autonomous, safe-only, or manual — switch live with /permissions or shift+tab, and risky shell commands always escalate. Tool-event hooks run your own shell checks before and after every tool call; a non-zero exit blocks the action. Every turn is saved locally, so work survives a crash and resumes exactly where you left off — on your disk, not a cloud account. And it ships as a self-contained build with one install script, deployable on a locked-down or air-gapped workstation in minutes.

Who it’s for

Regulated industries with data-residency constraints, teams guarding proprietary IP and trade secrets, agencies and consultancies handling code under strict NDA, and any secure or air-gapped environment that has to keep the AI and keep the code at the same time.

Screenshots