Enterprise

Give agents access to your code. Keep control of it.

Single sign-on, precise roles, a complete activity log and branches with no public address come with every workspace. Nothing on this page is an add-on.

Controls

01Identity

Sign in the way your company already does.

  • Single sign-on over SAML or OIDC through your identity provider.
  • Google, Microsoft, GitHub and Apple sign-in, each switchable per deployment.
  • Authenticator-app two-factor, required for every organization by default.
  • People with a verified company email domain join automatically; personal email domains never do.
  • Sessions last at most seven days and end after a day idle; admins can revoke them.

02Access

Permissions as precise as your org chart.

  • Workspace, organization and project roles, from read-only to admin.
  • Custom roles built from allow and deny rules, where deny always wins.
  • Roles granted to people, nested teams or service accounts.
  • A documents-only role for people who should never see code.
  • Branch rules: required reviews and checks, linear history, signed commits, no force-pushes, with named exceptions.

03Audit

Know who did what, and whether it was allowed.

  • Every sign-in, push, branch change, review, merge, CI run and permission change is recorded.
  • Secret, environment and settings changes, and every AI model call, are recorded too.
  • Each entry records who, what, where, when and whether it succeeded or was denied.
  • Owners and admins filter the log by action, person, result, organization and time.

04Isolation

Branches with no public address.

  • The browser talks to one authenticated gateway; branches have no public network address of their own.
  • Secrets are encrypted with AES-256-GCM, scoped to a project or environment, and never shown again after saving.
  • Secrets reach a branch as a file read once and deleted, never as environment variables a terminal or agent could inherit.
  • Admins can shorten how long a branch’s credentials live, down from a maximum of eight hours.

05AI

Agents on your terms.

  • Each person can link their own Claude, ChatGPT or Google account; projects can hold their own API keys.
  • Those credentials are encrypted and never sent to a branch; model calls are made on the person’s behalf.
  • Choose the default coding agent per project: Claude Code, Codex, Gemini or the built-in agent.
  • Agents work under the same permissions, branch rules and reviews as people.

06Hosting

Where it runs.

  • ReasonOS runs on Google Cloud today, in the United States.
  • Each cloud gets its own control plane, so your workspace and its data stay in the cloud you chose.

Coming soonDirectory sync (SCIM) · Audit log export · AWS and Azure · SOC 2 report

Talk to us

Bring your security questionnaire. We will answer it line by line.

Write to [email protected] and we will walk your team through how ReasonOS handles identity, access, data and agents.