tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

Where your coding agent actually runs

Work out which half of your coding agent runs on your machine and which half runs in a vendor's cloud, before a client asks you.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

A client sends you a contract with a clause about third-party processing, or an NDA that says their source stays inside your control. You already run a coding agent in a terminal on your own laptop, so the answer feels easy. The code never leaves the machine. You wrote the reply in your head before you finished reading the clause.

The reply is wrong, and the reason is worth ten minutes of your time. Every coding agent is two separate machines wearing one product name: a model that decides what to do, and an execution environment that opens files and runs commands. Those two halves can sit in different places, owned by different companies, under different retention rules, and in most setups they do. Knowing which half is where is the difference between an accurate answer to that clause and a confident one. This guide is for freelancers and small teams who take other people’s code onto their machines. If you have a platform team and a signed enterprise agreement, they have already made these choices for you.

A coding agent is two machines wearing one name

Call them the brain and the hands. The brain is model inference: your prompt, the file contents the agent chose to read, the output of every command it ran, all packed into a request and sent to a vendor’s API. The hands are the process that lists your directory, edits the file, runs the test suite and holds the git credential. Anthropic describes the local case plainly: Claude Code runs locally, and to interact with the model it sends data over the network, including all user prompts and model outputs, encrypted in transit with TLS 1.2 or later [2].

The two halves have different failure modes, which is why it helps to stop thinking of the agent as one thing. A problem with the hands is a blast-radius problem: the agent deleted the wrong directory, pushed to the wrong branch, or reached an internal service it should not have. A problem with the brain is a disclosure problem: something a client owns is now sitting in a log on someone else’s infrastructure for some number of days. Tools that reduce one do not automatically reduce the other, and vendors sell controls for each separately.

On the hands side the controls are concrete. Codex sandboxes local execution with platform-native enforcement, Seatbelt on macOS, the native Windows sandbox in PowerShell and bubblewrap on Linux and WSL2, and defaults to a workspace-write mode where the agent reads files, edits inside the workspace and runs routine local commands within that boundary, with read-only and danger-full-access on either side of it [6]. Claude Code in manual mode starts read-only, can only write to the folder it was started in and its subfolders, and does not auto-approve commands that fetch from the web such as curl and wget [1]. Those are all statements about the hands. None of them says anything about what the brain receives.

Local execution does not mean local code

This is the part people get wrong in client conversations. Running the agent on your laptop keeps the checkout, the build output and the credentials on your laptop. It does not keep the content out of the vendor’s API, because the content is the input to the thing you are paying for. The model cannot suggest a fix to a file it has not read.

Anthropic states the boundary directly on the page describing its self-hosted deployment. Even when sessions execute on hardware you own, repository checkouts, build artifacts, secrets and any files a session creates or modifies stay on the machines you provision, while the conversation itself, including prompts, responses and tool results, goes to api.anthropic.com for model inference, and Anthropic stores the session transcript so you can resume from another supported surface [3]. Cursor says the same thing about its self-hosted workers, which transmit file contents, terminal output, diffs, screenshots, local MCP results and routing metadata back to Cursor [4]. Cognition’s Devin Outposts, announced on 21 July 2026, executes sessions on machines you operate while Devin’s agent loop stays in Cognition’s cloud [8].

Three vendors, three architectures, one shared rule. Execution moves. Context does not. If your client’s requirement is that no third party ever processes their source, no configuration of a hosted coding agent satisfies it, and the honest answer is that you would have to run a model yourself. If the requirement is that their code is not stored, not trained on, and not sitting in a vendor’s sandbox, that is a different requirement and you can meet it.

The four places the hands can live

The first arrangement is the one you already use: agent and code both on your machine, in a terminal or an IDE. The brain is remote, everything else is yours, and your exposure is a stream of API requests plus whatever the tool writes to your own disk. It is the cheapest arrangement to reason about and the easiest to explain to a client.

The second is the vendor’s cloud. Start a session from a browser and your repository is cloned to an isolated, vendor-managed virtual machine. In Anthropic’s case GitHub authentication is handled through a secure proxy so your actual credentials never enter the sandbox, all outbound traffic goes through a security proxy for audit logging and abuse prevention, git push operations are restricted to the current working branch, and session VMs are reclaimed after a period of inactivity [1][2]. That is a genuinely well-fenced environment, but a copy of the client’s repository now exists somewhere you do not own, which is the specific fact some contracts care about.

The third is the split itself: the vendor’s brain driving hands that run on your infrastructure. Anthropic calls this a self-hosted environment, where you run a program called a runner inside your network, the control plane places a queued session on the environment’s queue, and a runner claims it, clones the repository and starts a Claude Code process on your host; the traffic to Anthropic is outbound HTTPS, and Anthropic never connects into your network [3]. Cursor’s version moves cloud-agent tool execution to a machine you manage, with workers dialling out to api2.cursor.sh and api2direct.cursor.sh for session communication and to an S3 bucket for artifacts, and no inbound ports, public IPs or VPN tunnels required [4]. Devin Outposts runs the same pattern across VMs, Kubernetes clusters, GPU boxes and Mac minis, and states that your machines only dial out, with no inbound connectivity required [8].

The fourth is a control split rather than an execution split, and it is the one most solo operators will actually use. Anthropic’s Remote Control connects the web interface to a Claude Code process running on your local machine, so all code execution and file access stays local, while the session transcript is stored on Anthropic servers to sync the conversation across devices [1]. No cloud VMs or sandboxing are involved. You get the phone-on-the-couch workflow without a second copy of the repository existing anywhere.

Retention and training are set on the brain, not the hands

Once you accept that context reaches the API regardless of where execution happens, the questions that matter are how long it is kept and whether it trains anything. Those are account settings, and they are frequently set on the wrong account, because the plan you buy for yourself and the plan you use for a client are often not the same one.

Anthropic’s split runs along consumer and commercial lines. On Free, Pro and Max, you choose whether your data is used to improve future Claude models, and Claude Code inherits that choice; leaving it on carries a 5-year retention period, turning it off gives you 30 days [2]. On Team, Enterprise and the API, Anthropic does not train generative models using code or prompts sent to Claude Code under commercial terms unless the customer has chosen to provide data for model improvement, for example through the Development Partner Program, and standard retention is 30 days [2]. Zero data retention exists but is not included in the standard Enterprise plan; it is enabled on a per-organisation basis by your account team after confirming eligibility [2]. OpenAI draws the same line for its business products, stating that by default it does not use your business data for training its models, that it may securely retain API inputs and outputs for up to 30 days to provide the services and identify abuse, and that zero data retention can be requested for eligible endpoints [7]. Cursor’s Privacy Mode is the equivalent switch, described as ensuring your code is never used for training by Cursor or other AI model providers, on by default for Enterprise teams and enforceable organisation-wide so members cannot disable it, with the caveat that Cursor’s zero-retention agreements do not apply when you use your own API keys [5].

There is a local retention story too, and it is the one nobody configures. Claude Code stores session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default so sessions can be resumed, adjustable with cleanupPeriodDays [2]. Transcripts you send with /feedback, /bug or /share are retained for 5 years, and a transcript you volunteer through the session quality survey follow-up is retained for up to 6 months, with known API key and token patterns redacted before upload but source code and file contents uploaded as-is [2]. If a client’s code is sensitive enough to argue about, it is sensitive enough not to attach to a bug report.

Credentials and network access are what self-hosting really buys

Strip out the disclosure question and the split architecture still earns its place, because the hands are the half that touches things that can be stolen or broken. Sessions run inside your network and can reach internal services, databases and registries without exposing them to the public internet, and the runner authenticates to your git host with credentials you configure rather than credentials you handed to a vendor [3]. Under Cursor’s arrangement the full checkout, build cache and machine-local credentials stay on the machine you manage [4]. Under Devin’s, sessions run as an unprivileged user with your repos, toolchains and internal services as they exist on that box [8].

For a freelancer, the practical version of this is smaller and more useful than the enterprise framing suggests. Your .env files, your client’s staging database, your deploy keys and your password manager all live on one laptop, and an agent with a shell has the same reach you do. That is an argument for sandboxing the hands whether or not anything is self-hosted: keep the working directory boundary on, keep the network commands unapproved, and use a dev container or a virtual machine for anything that runs scripts or makes tool calls against external web services, which is Anthropic’s own advice for working with untrusted content [1].

It is also worth knowing where the self-hosted route stops being available to you. Anthropic’s self-hosted environments are in public beta on Team and Enterprise plans, off by default, unavailable for organisations with zero data retention enabled, and unable to route inference through Amazon Bedrock, Google Cloud’s Agent Platform, Microsoft Foundry or an LLM gateway [3]. Cursor’s team pools require the Enterprise plan and service account authentication, though its per-user machines are available on standard plans, with a ceiling of 200 workers per user and 1,000 per team [4]. If you are one person with three clients, the realistic split is local hands with the retention setting checked, not a runner fleet.

checklist
Before you point an agent at a client's repository
0 of 8 · saved in this browser only

What to check before you sign

Read the clause for what it actually restricts. A clause about storage is answerable with retention settings and a sentence about where the checkout lives. A clause about training is answerable with a plan type and a switch. A clause about any third-party processing is not answerable by a hosted agent at all, and pretending otherwise is the version of this that ends badly.

Then name the vendor. A client who knows which company runs the model, on what terms, and with what retention is having a smaller conversation than one who finds out during a security review. Putting “model inference is performed by Anthropic under commercial terms with a 30-day retention period” [2] into the contract is a sentence you can defend line by line. If you cannot state the equivalent sentence for the tool you use, that is the gap to close before the next project rather than the next clause.

What still goes wrong

The split does not remove the disclosure question, it relocates it, and vendors’ own documentation says so more clearly than most summaries do. The wrinkle that catches people out is that the strictest controls are sometimes mutually exclusive: Anthropic’s self-hosted environments are unavailable for organisations with zero data retention enabled [3], so the setup that keeps the checkout in your building is not the setup that keeps the transcript out of the vendor’s storage. You pick one.

Prompt injection also gets worse, not better, as the hands move closer to things you care about. A session running inside your network can reach internal services precisely because that is the point of running it there [3], which means malicious text in an issue, a dependency or a fetched page has a more interesting environment to act in. Anthropic is explicit that while these protections significantly reduce risk, no system is completely immune to all attacks, and that you are responsible for reviewing proposed code and commands for safety before approval [1]. The permission modes and sandboxes are real controls, not a substitute for reading the diff.

Finally, this is a moving target. Self-hosted execution is in public beta at Anthropic [3], Cursor gates team pools behind Enterprise [4], and Cognition shipped Outposts in July 2026 [8]. Each of those is a current state rather than a permanent one. The architecture is durable; the specific row in the pricing table is not. Check the vendor’s data-usage page on the day you make a promise, not the day you read a guide.

sources
  1. 01Anthropic — Claude Code securitycode.claude.com
  2. 02Anthropic — Claude Code data usagecode.claude.com
  3. 03Anthropic — Self-hosted environmentscode.claude.com
  4. 04Cursor — Self-hosted machines for Cloud Agentcursor.com
  5. 05Cursor — Privacycursor.com
  6. 06OpenAI — Codex sandboxinglearn.chatgpt.com
  7. 07OpenAI — Enterprise privacyopenai.com
  8. 08Cognition — Introducing Devin Outpostsdevin.ai
next guide
Give your AI agents their own keys
9 min · verified 2026-09-05
related guides