Reduce AI costs without giving up control of your source code
The short answer
Access is scoped by the credential, never by anything the client sends. An agent is granted read scopes, its queries are checked before they run and executed in a read transaction, and the organisation those queries can see is taken from the token rather than from a request body. So cutting your AI costs does not mean loosening who can read your code.
The four things that hold
- OAuth 2.1 with PKCE. The same flow Claude and ChatGPT already speak. Refresh tokens rotate, and replaying a spent one revokes the session rather than quietly failing.
- Read-only by construction. Agent queries are checked before they run and executed in a read transaction, so a write is rejected twice over rather than relying on either check alone.
- Tenancy from the token. Your organisation id is never read from a request body, which is what stops one account reaching into another.
- Revoke in one click. Disconnecting an agent kills its tokens immediately, not at their next expiry.
| codemesh:code.read | search and read files |
| codemesh:query.read | structural queries |
| codemesh:repos.read | repository metadata |
| MATCH (n) DETACH DELETE n | a write, inside a read transaction |
| MATCH (n) RETURN n | no tenant filter |
| CALL apoc.load.json(...) | reaches outside the graph |
What actually leaves your machine
Scoping decides who can read the graph. This decides what is in it. Both matter, and the second one is the question developers ask first.
Read on your machine
- Source code and file structure
- Relationships between files
- Commit history, including author names and email addresses
- Commit messages
- Uncommitted work: working tree, staged changes, stashes
- Git config and remote URLs, credentials stripped
- The repository's path on the machine that synced it
Where it lands
The parsed structure and the source text, scoped to your organisation.
On Free, Basic and Team your graph shares an instance with other customers, and the separation between them is enforced by CodeMesh rather than by separate infrastructure. A dedicated instance is available on request.
Accounts, organisations, memberships, sessions, billing references, audit events and tool-call logs.
Also recorded about your use
- Your IP address and browser user-agent, against each sign-in, tool call and audit event
- A preview of what you asked our tools to do: search terms, questions, file paths, graph queries
- Audit events and tool-call logs are retained indefinitely today. A retention period is being defined.
Never happens
- No analytics, advertising, session recording or third-party tracker anywhere in the product
- Your code is never used to train machine-learning models
- Personal information is never sold
- Card details are entered with the payment provider and never reach CodeMesh
- No marketing email from this product
Where each piece runs
Three arrangements, differing only in who holds the graph and which model endpoint your agent talks to. The extension and the daemon are on your machine in all three.
The default. Your graph lives on a database instance alongside other customers, and the separation between them is enforced by CodeMesh rather than by separate infrastructure.
Do you train models on my code?
Does my machine hold a database credential?
Who inside my organisation can see what?
What about third-party apps I authorise?
Read the full data policy
Every item above, stated in full, with the parts that are uncomfortable left in.