Developers code with srooterctl. Every request goes through the srooter API, where your team sets routing, budgets and policy once. Teams that keep Claude Code or Codex can opt in to routing them through srooter. The table below shows which controls apply to each client.
Forward this page internally. Each answer names the mechanism your security review can check.
One install and one sign-in: srooterctl login, then srooterctl to code. Teams that keep Claude Code or Codex opt in per client with srooterctl enable claude or enable codex. Cursor and aider point at the OpenAI-compatible endpoint. Start with one repository; Srooter indexes it and the harness applies from the next task.
srooterctl coding CLI · opt-in client routing · OpenAI- and Anthropic-compatible endpointPractice and model policy are set at the org level and apply per task. Exceptions are requested in-session and approved by the roles you designate; every exception is recorded in the audit ledger with who, what and why.
policy engine · allowlists · audit ledgerRequests to the models you allow, routed through Srooter or your self-hosted gateway. The audit log keeps a hash of each prompt, not its text. Conversation transcripts are kept under a 30-day default retention setting, encrypted on the managed service (self-hosted: depends on your key setting), and an org admin can turn them off. Your code never executes in Srooter; tests run in your CI. Sensitive repos can be pinned to local models; with a self-hosted gateway, their requests stay in your network.
hashed audit · transcript capture you control · client-side test execution · Ollama / sovereign endpointsCircuit breakers detect the outage. Transport failover moves the session to an alternate provider without a quality downgrade and keeps it there for the session. Over budget, requests go to a lower-cost model instead of failing, and the ledger records it.
circuit breakers · session-sticky transport failover · budget downgradesrooter ships the code graph, task memory, review council and decision ledger as one system that uses your repository’s code graph, under central policy and audit. You do not have to wire them together or keep them in sync.
Cortex code graph · Mnemos · Council · provenance$39 per seat on Team, $79 on Enterprise, plus tokens at provider cost plus a 10% gateway fee (no token fee on your own provider keys), with routine work routed to efficient models. Routing adds a single in-band pass. Operations: a hosted service, or a gateway you run with auto-update.
seats + tokens at provider cost + 10% · one in-band routing pass · managed or self-hostedsrooter servers never run your code. Tests run in your CI. Sensitive repositories can be pinned to local models on a self-hosted gateway, so their requests stay in your network.