Repository-local outputs
The CLI writes configuration, deliverables, and trace records under .devrel/ in the repository where it runs.
Security / Current posture
This page separates the behavior of the open-source CLI from the roadmap for the managed product. It avoids guarantees that are not represented by a current public control or contract.
Repository
Provider
Workspace
Human gate
No automatic publish stepVerifiable behavior
The CLI writes configuration, deliverables, and trace records under .devrel/ in the repository where it runs.
Initialization asks you to configure Anthropic or OpenRouter. Generation requests are governed by the provider and account you choose.
The setup flow writes the provider key to .devrel/.env with restricted local file permissions.
Origin produces reviewable files. Your Git workflow determines what is committed, merged, or published.
The CLI operates in the repository where you invoke it and writes its working files under .devrel/. Review those files before committing them, and use repository permissions to control who can read the resulting artifacts.
Origin sends generation requests to the provider configured during setup. Review that provider's retention, training, regional processing, and account terms for the specific plan you use. The website does not claim a universal zero-retention agreement.
Origin Cloud is presented as a private-beta path. SOC 2 Type II remains on the roadmap and is not described as a current certification. Deployment, deletion, export, and subprocessor commitments should be confirmed in the applicable agreement before managed use.
Send a concise reproduction, affected version, and impact to daria@gtm-labs.co. Avoid including secrets or customer repository content in the initial report.