SECURITY · PRIVATE BETA

Know the boundary before Fee crosses it.

Fee combines local project work with routed AI models. The important question is not whether data moves, but what moves, why it moves and what evidence comes back.

Local secrets and excluded filesRouted selected prompt and contextRecorded model, usage, cost and approvals

THE SHORT VERSION

Useful controls, stated without overclaiming.

Flatfee does not claim that the private beta is suitable for every security or residency requirement. Use the boundaries below to decide whether a project belongs in Fee today.

01

What should stay local

Raw API keys, proxy tokens, cookies, signing credentials and excluded files should not be sent as model context. Fee's local context policy and redaction controls are designed to keep those categories out, but users still need to select the right workspace and avoid pasting secrets into requests.

02

What can cross the proxy

The prompt and project context you select may be sent to the provider chosen for that step. The provider and processing region depend on the route. Fee does not currently offer an EU-only model-processing option.

See the current model approach →
03

Approvals and workspace control

Fee works inside the project you select. When a material decision or new permission is needed, the agent should pause and explain what is blocked. Routine steps follow the mode you chose; risky action should never be hidden behind an ambiguous status.

04

Evidence after the task

Task reports can record request identifiers, route and model metadata, usage, cost, timing, approval summaries and file or result hashes. They should not contain prompt bodies, raw provider payloads, cookies or secret values.

BEFORE YOU START

Choose a project whose data can follow the selected route.

If a project has strict residency, confidentiality or contractual requirements, review them before using the beta. Fee's private-beta controls are not a substitute for your organisation's security decision.

Read the privacy summary