For platform and security engineering

A governed coding CLI for teams.
One policy, set centrally.

Developers code with srooterctl. Every request goes through the srooter API, where your team sets routing, budgets and policy once. Teams that keep Claude Code or Codex can opt in to routing them through srooter. The table below shows which controls apply to each client.

ORG POLICY · acme-platformsrooter.yaml
practice:
tdd: required # tests before implementation
validation: functional + visual
review: council # independent of author model
models:
allow: [glm-5.3, claude-*, ollama/qwen3]
sensitive_repos: ollama/* # never leaves your infra
budget.team.payments: $4,000/mo · on_exceed: downgrade
governance:
sso: okta · residency: eu-west · audit: on
exceptions: approved-by platform-leads
THE CHECKLIST

Six questions for your platform and security review.

Forward this page internally. Each answer names the mechanism your security review can check.

01

What do developers install or change?

One install and one sign-in: srooterctl login, then srooterctl to code. Teams that keep Claude Code or Codex opt in per client with srooterctl enable claude or enable codex. Cursor and aider point at the OpenAI-compatible endpoint. Start with one repository; Srooter indexes it and the harness applies from the next task.

srooterctl coding CLI · opt-in client routing · OpenAI- and Anthropic-compatible endpoint
02

What can developers bypass, and who approves exceptions?

Practice and model policy are set at the org level and apply per task. Exceptions are requested in-session and approved by the roles you designate; every exception is recorded in the audit ledger with who, what and why.

policy engine · allowlists · audit ledger
03

What leaves our infrastructure?

Requests to the models you allow, routed through Srooter or your self-hosted gateway. The audit log keeps a hash of each prompt, not its text. Conversation transcripts are kept under a 30-day default retention setting, encrypted on the managed service (self-hosted: depends on your key setting), and an org admin can turn them off. Your code never executes in Srooter; tests run in your CI. Sensitive repos can be pinned to local models; with a self-hosted gateway, their requests stay in your network.

hashed audit · transcript capture you control · client-side test execution · Ollama / sovereign endpoints
04

What happens when Srooter or a provider is down?

Circuit breakers detect the outage. Transport failover moves the session to an alternate provider without a quality downgrade and keeps it there for the session. Over budget, requests go to a lower-cost model instead of failing, and the ledger records it.

circuit breakers · session-sticky transport failover · budget downgrade
05

Why this instead of agent config plus CI plus an open-source harness?

srooter ships the code graph, task memory, review council and decision ledger as one system that uses your repository’s code graph, under central policy and audit. You do not have to wire them together or keep them in sync.

Cortex code graph · Mnemos · Council · provenance
06

What does it cost in money, latency and operations?

$39 per seat on Team, $79 on Enterprise, plus tokens at provider cost plus a 10% gateway fee (no token fee on your own provider keys), with routine work routed to efficient models. Routing adds a single in-band pass. Operations: a hosted service, or a gateway you run with auto-update.

seats + tokens at provider cost + 10% · one in-band routing pass · managed or self-hosted
DATA BOUNDARIES

Where requests go, and what srooter stores.

srooter servers never run your code. Tests run in your CI. Sensitive repositories can be pinned to local models on a self-hosted gateway, so their requests stay in your network.

STAYS WITH YOU
✓Code execution · srooter servers never run your code; tests run in your CI
✓Sensitive repositories · pinned to local or sovereign models by policy
✓Provider credentials · BYOK, encrypted at rest, per org
✓Your region · data residency pinning per org
GOES TO SROOTER (OR YOUR SELF-HOSTED GATEWAY)
→Model requests · to the providers you allow, through the gateway
→Prompts and transcripts · the audit log stores a SHA-256 hash of each prompt, not its text; transcripts are stored with admin-controlled retention (30-day default), encrypted on the managed service
→Code graph index · symbols and edges for context assembly, or on your self-hosted gateway
→Task memory · typed, per-session, with decay and eviction
→Audit records · every routing and review decision, exportable
KEEP YOUR TOOLS

Keep an existing coding client. Route its requests through srooter.

CONTROL
srooterctl
Claude Code
Codex
Cursor
aider
Context and knowledge
●
●
●
●
●
Memory
●
●
●
●
●
Model policy and budgets
●
●
●
●
●
Engineering practice
○
●
●
●
●
Gates in your CI
●
●
●
●
●
Independent review
●
●
●
●
●
Audit and provenance
●
●
●
●
●
availableon the roadmap
DEPLOYMENT

Centrally managed. Runs where you need it.

Cloud SaaSMulti-tenant, api.srooter.ai
Live
Self-hosted gatewaySingle-tenant, your infrastructure, auto-update
Available
BYOKYour provider keys, encrypted at rest
Available
Local and sovereign modelsOllama and internal endpoints
Available
SSO · data residency · audit exportOIDC / SAML, region pinning, ledger export
Available
Full VPC harness · HelmComplete harness inside your VPC
Talk to us
Cloud marketplacesAWS · Azure · GCP procurement
Roadmap
ROLLOUT

Start with one repository. Expand by policy.

  1. Week 1
    One repository, one teamIndex the repo, connect the agents, apply your existing standards as policy.
  2. Week 2
    Turn on review and validationCouncil review with srooterctl review, and functional plus visual validation of changes. Watch the audit ledger.
  3. Week 3
    Set model policy and budgetsAllowlists, risk-tier routing, per-team budgets, sensitive repos on local models.
  4. Then
    Extend policy to more teamsNew repos and teams inherit the harness. Developers keep choosing their tools.
# developers install once, then code
curl -fsSL api.srooter.ai/install.sh | bash
srooterctl login
srooterctl # every request through your gateway

See srooter on your stack.
Start with one repository and one team.

Get Started →See enterprise pricing
srooter> · the governed coding CLI for teams