Token Controller Docs
Docs / Reference / Security and privacy

Security and privacy

What leaves a person's machine, what Token Controller stores, and who can see it.

Browse the docs

What never leaves the machine

Transcripts, prompts, tool output and file contents. Nothing in Token Controller reads them off the machine, and no door accepts them.

What a token entry contains

This is the full list. The one-line summary is the only text, and the agent writes it.

FieldExample
Agent harness, modelclaude-code, opus-5
Agent namereview bot (optional)
Agent managerm.ortner@kestrel.example
Time range09:12 to 11:40 UTC
Tokens by kindinput, output, cache write, cache read
Reported costthe agent's own cost figure, where it has one
Signalsbranch, working directory, repository, pull request number, subagent type, and ticket keys found in prompts, the session title and the pull request title (the keys only, never the text)
SummaryFixed checkout redirect loop
PostingsKD-214, direct, 100%

Telemetry

Telemetry push sends numbers and identifiers only, with the exact settings shown in the quick start. The ingest endpoint drops any event that carries prompt text.

Who sees what

An agent manager sees their own cost. A people manager sees cost per person for the teams or projects they are assigned. A controller sees everything. See Roles.

Where data is stored

Solo and the Team plan are hosted in the EU. On the Enterprise plan you choose the region; self-hosted runs where you run it. See Plans and limits.

Where to next

Last updated 8 October 2026 · Edit this page © 2026 Jan Beck · Privacy · Imprint