nittim Enterprise runs the entire audit inside your own AWS account. Not a data-processing agreement about where your code goes — an architecture in which it has nowhere else to go.nittim Enterprise runs the whole check inside your own AWS account. This isn't a paper promise about where your code goes — it's a setup where your code genuinely has nowhere else to go.nittim Enterprise runs the whole audit inside your AWS account — your code has nowhere else to go.
In your VPC
Your code stays put
A component you operate fetches the repository — including GitHub Enterprise inside your network — and runs the deterministic evidence layer. You get its full source, and it verifiably contains no audit logic.A component you run yourself fetches your project's code — including from GitHub Enterprise inside your own network — and runs the rule-based, fact-finding layer. You get its full source code, and can verify for yourself that it contains no AI reasoning logic.A component you run fetches the repo — including GitHub Enterprise on your network — and runs the deterministic evidence layer. Verify its full source: no audit logic in it.
Sealed, in your account
The analysis happens in-house
nittim's audit engine runs as a sealed service deployed inside your account. It receives only the prepared audit input, returns the finished report, and persists nothing. Confidential-computing attestation is the roadmap; the sealed image is today.nittim's checking engine runs as a locked-down service deployed inside your own account. It only receives the prepared input, hands back the finished report, and keeps nothing afterward. Cryptographic proof that the sealed environment wasn't tampered with is on the roadmap; the locked-down image itself is available today.nittim's audit engine runs sealed, inside your account: takes the input, returns the report, keeps nothing. The sealed image ships today; attestation is on the roadmap.
Your model bill
Claude, via Bedrock, in your account
The model call happens through AWS Bedrock in your own account and region. nittim never proxies your code to anyone — and you pay AWS directly for model usage, at cost.The AI call happens through AWS Bedrock (Amazon's AI hosting service) in your own account and region. nittim never routes your code through anyone else — and you pay AWS directly for AI usage, at cost.Model calls run through AWS Bedrock in your own account — nittim never proxies your code, and you pay AWS directly for model usage, at cost.
What nittim never sees
Your code. Your findings. Your reports. Even the fact that a particular audit ran. Billing reconciles from signed usage receipts your side exports — counts and salted hashes, never repository names — so the license can be metered without a single byte of telemetry leaving your account on its own. The other direction is protected the same way: the audit engine is the licensed asset, sealed by packaging and license rather than by promise. The boundary contract in the evaluation kit spells out exactly what crosses it — in both directions.Your code. Your findings. Your reports. Even the fact that a particular check ran at all. Billing is worked out from signed usage records your own side exports — counts and scrambled ids, never project names — so we can charge for the license without a single byte of tracking data ever leaving your account on its own. The other direction is protected the same way: the checking engine is the thing we license to you, locked down by how it's packaged and licensed, not just by a promise. The written boundary agreement in the evaluation kit spells out exactly what crosses that line — in both directions.nittim never sees your code, findings, or reports — not even that an audit ran. Billing runs on signed usage receipts you export: counts and salted hashes, no repo names, no telemetry leaving your account. The audit engine is the licensed asset, sealed by packaging and license, not promise. The kit's boundary contract spells out exactly what crosses, both ways.
The management plane is already here
Enterprise deployments plug into the same organization layer the hosted product runs on: SSO, per-organization isolation, an append-only audit log of every action, and policy-as-code through a config file your repos already carry. Self-hosted (enclave/clientpod) deployments read .fis.yml; the hosted nittim audit path also reads .nittim.yml. Either way, the verdict gate in CI enforces your policy, not just ours.Enterprise deployments plug into the same team-management layer the hosted product runs on: SSO (one login for your whole company), each team's data kept separate, a record of every action that nobody can quietly edit (an audit log), and policy-as-code — your own rules, written into a settings file your projects already carry. Self-hosted (enclave/clientpod) deployments read .fis.yml; the hosted nittim check path also reads .nittim.yml. Either way, the pass/fail gate in your CI (your automated build-and-test pipeline) enforces your rules, not just ours.Enterprise deployments share the hosted product's organization layer: SSO, per-org isolation, an append-only audit log, and policy-as-code via a config file your repos already carry. Self-hosted deployments read .fis.yml; the hosted nittim audit path also reads .nittim.yml. Either way, CI's verdict gate enforces your policy.
Evaluate it properly
The evaluation kit contains the full source of the component that touches your code, the complete boundary contract, the deployment topology, and the architecture brief — everything your platform and security teams need to judge the design before a single conversation.The evaluation kit includes the full code for the one piece that touches your code, a plain description of exactly what it can and can't reach, how it's set up to run, and a written explanation of the design — everything your technical and security teams need to check it out before you even talk to us.The kit gives you the code-touching component's full source, boundary contract, deployment topology, and architecture brief — what your platform and security teams need before you talk to us.
Downloads are tied to your account, and we follow up personally — that's the whole funnel. Currently in the design-partner phase: annual license, scoped per organization.Downloads are tied to your account, and we follow up with you personally — that's the whole process. Right now we're working with a small number of design partners: an annual license, scoped to your organization.Downloads tie to your account, and nittim follows up personally — the whole funnel. Now in the design-partner phase: annual license, scoped per organization.
Wondering how accurate the audits are? The benchmark — corpus, method, and every caveat — is public: Wondering how accurate the checks are? The test results — what we tested, how, and every weakness we found — are public: How accurate are the audits? The benchmark — corpus, method, every caveat — is public: see the numbers.