Reduce AI costs without giving up control of your source code

The short answer

Access is scoped by the credential, never by anything the client sends. An agent is granted read scopes, its queries are checked before they run and executed in a read transaction, and the organisation those queries can see is taken from the token rather than from a request body. So cutting your AI costs does not mean loosening who can read your code.

The four things that hold

  • OAuth 2.1 with PKCE. The same flow Claude and ChatGPT already speak. Refresh tokens rotate, and replaying a spent one revokes the session rather than quietly failing.
  • Read-only by construction. Agent queries are checked before they run and executed in a read transaction, so a write is rejected twice over rather than relying on either check alone.
  • Tenancy from the token. Your organisation id is never read from a request body, which is what stops one account reaching into another.
  • Revoke in one click. Disconnecting an agent kills its tokens immediately, not at their next expiry.
token scoperead only
What an agent is granted
codemesh:code.readsearch and read files
codemesh:query.readstructural queries
codemesh:repos.readrepository metadata
What it is refused
MATCH (n) DETACH DELETE na write, inside a read transaction
MATCH (n) RETURN nno tenant filter
CALL apoc.load.json(...)reaches outside the graph

What actually leaves your machine

Scoping decides who can read the graph. This decides what is in it. Both matter, and the second one is the question developers ask first.

Read on your machine

  • Source code and file structure
  • Relationships between files
  • Commit history, including author names and email addresses
  • Commit messages
  • Uncommitted work: working tree, staged changes, stashes
  • Git config and remote URLs, credentials stripped
  • The repository's path on the machine that synced it

Where it lands

Your graph, on CognoDB

The parsed structure and the source text, scoped to your organisation.

On Free, Basic and Team your graph shares an instance with other customers, and the separation between them is enforced by CodeMesh rather than by separate infrastructure. A dedicated instance is available on request.

Our own database

Accounts, organisations, memberships, sessions, billing references, audit events and tool-call logs.

Also recorded about your use

  • Your IP address and browser user-agent, against each sign-in, tool call and audit event
  • A preview of what you asked our tools to do: search terms, questions, file paths, graph queries
  • Audit events and tool-call logs are retained indefinitely today. A retention period is being defined.

Never happens

  • No analytics, advertising, session recording or third-party tracker anywhere in the product
  • Your code is never used to train machine-learning models
  • Personal information is never sold
  • Card details are entered with the payment provider and never reach CodeMesh
  • No marketing email from this product
Technical note
On the Free, Basic and Team plans your graph shares a database instance with other customers, and the separation between them is enforced by CodeMesh rather than by separate infrastructure. If that is not acceptable for your code, the dedicated and on-premises options below exist for exactly that reason.

Where each piece runs

Three arrangements, differing only in who holds the graph and which model endpoint your agent talks to. The extension and the daemon are on your machine in all three.

The default. Your graph lives on a database instance alongside other customers, and the separation between them is enforced by CodeMesh rather than by separate infrastructure.

SharedFree, Basic and Team
Editor extension and sync daemonYour machineOn your machine, watching your working tree
Your code graphManaged by usA shared instance, scoped to your organisation
The model your agent callsYour machineWhichever provider your agent already uses

Do you train models on my code?

No. Your code is never used to train machine-learning models.

Does my machine hold a database credential?

No. Your machine and your coding agent never hold one. Every query is scoped by the credential itself, executed read-only, and only the result crosses back.

Who inside my organisation can see what?

Members can query the graph subject to their role, and every member can see an activity view covering the last 90 days, which includes other members' email address, IP address, browser user-agent and a preview of the queries they sent. If that is not appropriate for your team, do not connect repositories you are not willing to share at that level.

What about third-party apps I authorise?

The scopes you grant on the authorisation screen decide what they can read, and the read scope covers structural queries across your graph, including git metadata and commit author details. Review what you are granting, and revoke grants you no longer use.

Read the full data policy

Every item above, stated in full, with the parts that are uncomfortable left in.

Read the data policySee the Benchmark