Required for the site to work (login, preferences, security). Always on.
Does a coding agent’s cloud index mean customer code stayed on the technician’s laptop?
No. A default or silent cloud index, a Repo Wiki or a workspace snapshot is a residency and custody control: running on the technician’s laptop does not prove the customer’s code stayed there.
An MSP hears a familiar line from the buyer: the assistant runs on the technician’s machine, so the customer repository never leaves. The answer, in the first two sentences, is no. A default or silent cloud index, a Repo Wiki, or a workspace snapshot is a residency and custody control, not a convenience toggle.
The failure class is easy to name and should stay at that altitude. The whole workspace can leave the device. History and configuration can leave with it. This article does not describe how such a path is built. It answers what “running locally” does not prove, what the September 2026 ZCode coverage is allowed to stand for, which control catalogs apply, and what belongs in an MSP policy.
One limit sits in the opening, not in a footnote. Sentences about deletion, and sentences that say the material was not used for training, are company claims. They are not facts Altovar has verified. A star count, a marketing line, or a cleaned public tree does not upgrade those claims.

Buyers collapse three phrases into one comfort. A codebase index, a Repo Wiki, and a workspace sync are not the same product label, and an MSP should not treat them as the same button. They do share a custody meaning when any one of them places a copy, or a derivative of a copy, outside the endpoint. The interface can still say the agent is local. The index can still be somewhere else. Reading the adjective on the splash screen is not the control.
“The model is local” and “the index is local” are different sentences. A local window can call a cloud indexer, a cloud wiki generator, or a snapshot job without moving the chat pane off the laptop. The technician sees a process on the machine they already trust. The buyer hears “on-prem” because the keyboard is in the office. Neither observation answers where the tree, the history, or the configuration files went after the index ran. Local inference, when it is actually local, still says nothing about a side path that packages the workspace for a vendor store.
MSP life makes the mistake sharper. One technician laptop often holds more than one customer tree: a morning ticket in one repository, an afternoon change in another, clones left in a home directory because disk was cheap. A shared agent profile is a pooled path. It is one configuration, one login cache, and often one index setting applied across those trees. A clean identity-provider login on the technician’s own account does not create per-customer custody. It proves the technician authenticated. It does not prove each customer’s source stayed inside a boundary that customer would recognize as theirs.
Secrets travel with the tree. Keys left in environment files, continuous-integration tokens, SSH client configuration, and the history that records how those files changed are the same blast radius that ordinary secrets guidance already treats as a management failure. They are not an oddity that appears only when a model is involved. If a snapshot takes the workspace, it takes the litter in the workspace. Rotation, least privilege, and a refusal to let tooling become a silent exit are the old controls. An AI feature does not rename them.
An open-source drop of today’s client can prove a narrower thing. Someone can read the tree that is public now and see what that tree says it does. That reading cannot prove yesterday’s retention, yesterday’s deletion, or whether yesterday’s copies were used for training. A missing history is not a certificate that the missing history was harmless. The current files are evidence about the current files. Policy should say that out loud before a buyer treats a clone as a forensic close.
The ZCode episode is evidence of the class, not a reproduction. The facts below are limited to pages fetched on 3 October 2026 and to the desk file that fixed this angle on 23 September 2026. Nothing here is a method, a sample, or a way to go look for stored objects.
The Register, published 22 September 2026 at 16:59 UTC (18:59 Europe/Rome), reported that Z.ai apologized and that ZCode packaged and uploaded user workspaces, including project histories, to Alibaba Cloud. Decryption material was described as held on the server. Researcher Ferstar, as reported there, tied the behavior to Repository Index after Repo Wiki cloud pages, and the same report says there was no in-product off switch and no privacy-policy disclosure of that behavior. The company said the data was not used to train models. The company claimed that assessments by CAICT and NSFOCUS showed prior uploads deleted. Repo Wiki was removed. The project was open-sourced. Ferstar, again as reported, said the published tree no longer showed Repo Wiki and criticized a wiped pre-patch history. That page is The Register’s 22 September account.
InfoWorld, the same day, described a default-enabled workflow that sent local repositories to Alibaba Cloud without consent. It carried Ferstar’s description, via a machine translation the article itself flags, of silent packaging of git history, LFS cache, reflogs, and configs toward Aliyun object storage. The company said remediation landed in ZCode v3.14.0, that NSFOCUS confirmed a production bucket and its objects deleted, that Repo Wiki and the snapshot path were removed, and that the data “has never been used for model training.” Those deletion, bucket, training, and assessment sentences are vendor or press attributions. Treat them as claims. They are not Altovar-verified. Practitioner reaction on that page, from Semgrep’s Cris Thomas and Katie Paxton-Fear, belongs only as reaction: disclose egress, and default to minimum permissions rather than the widest ones. The page is InfoWorld’s 22 September report.
What the class supports, for a buyer, is the picture of a full workspace snapshot moving toward object storage, with decryption material described as server-held, and with git history inside the package. What it does not support is a claim that every coding agent does this, a claim that the named assessments closed the question, or a claim that a later public tree rewinds September. The desk note that locked these two URLs before this article was the 23 September Lane B FAQ. This piece does not add anecdotes that note did not have.
Three catalogs frame the same buyer mistake without turning this into a ZCode-only review. Each is adjacency or primary guidance as labeled. None was re-fetched for this stamp; the URLs are the ones quoted from the 23 September desk file.
The OWASP Secrets Management Cheat Sheet treats secrets hardcoded in source and configuration as a normal leak surface: API keys, credentials, SSH material, and similar litter. It asks for least privilege, a controlled life cycle, and tooling that does not become a silent exit for those secrets. When exposure happens, detection, revocation, and rotation are the response, not a shrug that the feature was convenient. A full-workspace upload is, in that framing, a secrets-management failure with a large radius, because the tree and the secrets in the tree move together. The sheet lives at the OWASP secrets cheat sheet. The desk file fetched it on 23 September 2026. This article did not fetch it again.
NIST Special Publication 800-53 Revision 5, in the catalog dated September 2020 with updates as of 10 December 2020, states AC-4 as information-flow control and SC-7 as boundary protection. AC-4 is about approved authorizations for where information may travel inside a system and between systems. SC-7 is about protecting the boundary and controlling communications at managed interfaces. Default agent egress of a customer workspace, with no approved flow and no managed decision to let that tree cross the boundary, misses those intents. It is not “local AI.” The portal page quoted from the same desk file is the NIST publication landing page, and the DOI is 10.6028/NIST.SP.800-53r5. Not re-fetched today.
The AWS Well-Architected SaaS Lens section on preventing cross-tenant access is adjacency, not an AWS finding about ZCode and not an audit of any coding-agent vendor. The section’s point is that tenant scope should come from a verified identity and that runtime should refuse another tenant’s resources. A shared coding agent that indexes many customer trees on one technician profile is the same class of boundary failure: pooled access, weak per-customer scope, and a login that looks clean because it authenticated the person rather than the customer boundary. The page quoted from the desk file is Preventing cross-tenant access. Calling that adjacency keeps the citation honest. It does not import an AWS verdict into a desktop agent.
Five asks belong in the MSP policy, each with a picture of evidence and a picture of what is not evidence. A marketing sentence is not evidence. A squashed public history is not evidence of what the product did before the squash. A star count is not evidence of custody.
First, default-deny or an explicit opt-in for any cloud index or workspace upload. Evidence looks like a setting export the customer can read, or a build policy that shows the index path off unless a named ticket turns it on. A banner that says “we take privacy seriously” is not that export.
Second, endpoint egress allowlists plus data-loss controls on technician machines that hold customer trees. Evidence looks like the allowlist, the exception log, and a ticket when a new host is added. A promise that “the agent is local” is not an allowlist.
Third, private or self-hosted inference where the customer contract requires residency. Evidence looks like the contract clause and the endpoint that actually serves the model, not a slide that says a private option exists somewhere on a price sheet. If the contract is silent, do not invent a residency duty the paper does not contain. If the contract is loud, the laptop process still has to match it.
Fourth, data-processing language that names what leaves the device, retention, subprocessors, and deletion evidence. A vendor assessment PDF is a claim until the customer can see the scope: what was in scope, what was sampled, and what “deleted” was asked to mean. The PDF’s adjective is not the scope.
Fifth, an open-source client drop audits today’s tree only. Evidence looks like a reading of the files that are in the repository now, dated and hashed to that reading. It does not look like a story about last month’s binary inferred from files that no longer contain last month.
The sentence a buyer can repeat is short. Do not equate “the agent runs on the laptop” with “customer code never left.”
Buyers will start writing “no silent workspace snapshot” next to “no training on our data,” and the second sentence will not cover the first.Speculation — MSP desk, not a sourced quote
The residual posture on application isolation is narrower than the custody question, and it should stay narrow. A live tenant-isolation check returned ok at 2026-10-03T02:22:33.738Z, which is 04:22:33 Europe/Rome. The shape was type m2m, sub app_6CQN4QRiAFcMoF48, aud au_hVn3e7UYQ23GRSja, tenant_id bound to cmou3qrd40000yi4pjmgq2sxa, org_id null, lifetimeSeconds 3600, probe ok, violations empty. The probe passed with a null org claim and did not list that null as a violation.
That result is an application isolation posture for MSP multi-tenant identity: a short-lived, tenant-bound machine token, and a probe that resolved. It is complementary to an endpoint policy about whether customer source may leave a laptop. It is not code custody. It is not a certification. It does not stand in for coding-agent egress controls, a processing agreement, or deletion evidence.
Auth language that this isolation call did not re-prove: four native planes are CLEAR. The deferred-honest list, which is not a plane clearance, still has to be said. GDPR getUser and sessions Admin remain deferred. advancedKeycloakService remains deferred. D1 SAML and D2 keycloakRealm remain deferred. SPID and CIE user-experience paths stay fail-closed. keycloakAlias stays on the deferred list. eIDAS stays never-synced. This is not a claim of an absolute binary-free estate, not a claim of an Admin-API-free estate, and not a claim that no Keycloak process exists. Joint-clear anchors d7a8bfbc and docs tip 119d335e are not something today’s isolation call re-checked.
Gateway cost telemetry is skipped. It was not re-probed for this article. An earlier pulse file recorded a gateway denial on 23 September 2026; that note is not a fresh observation, and this piece invents neither a new denial time nor any usage figure.