Where your data goes.

Excellent runs locally by default. This page says what it reads, where it stores it, what can leave the machine, and what changes in team mode.

Local mode.

Database                  Local Excellent data directory
Artifacts                 Local Excellent artifact directory
Account required          No, not for local use
Cloud relay               Not required for local use
Processes with access     Excellent local service and approved child processes
Encryption                Release-manifest fact required before launch
Keys                      Release-manifest fact required before launch

Model providers.

Excellent does not need to proxy every model request. Your coding agent continues to use the provider account and settings you already chose. The context it sends to that provider is governed by that agent and provider, not by Excellent.

What Excellent may send.

Service                  Local mode
Data sent                None required for local use
Purpose                  Local verification and records
Destination              Your machine
Default state            Local
Retention                Controlled by local data deletion/export
Disable                  Do not enable hosted or team features

Optional team mode may send shared agent versions, experiments, checks, results, and receipts to the deployment you configure.

Secrets.

  • Secrets should be stored outside ordinary logs.
  • Logs should redact known secret values.
  • Subprocess environment variables should be scoped to the run.
  • Model context should exclude secrets unless explicitly approved.
  • Signing-key custody must be documented by the release manifest.

Checks and receipts.

A receipt proves which input, checks, evidence, decision, and software version were bound together. It does not prove that every external source was truthful. The result page shows where the evidence came from and which parts required judgment.

Team mode.

Team mode should be described from the actual deployment topology. Do not assume a customer-hosted server, customer-controlled cloud, or centralized account path unless that release has passed its deployment checks.

Report a problem.

Email security@excellent.so.

Include the affected version, the command or route involved, and the smallest reproduction you can share. We aim to acknowledge security reports within three business days.