Air-gapped · runs on your own GPUs

The coding teammate that runs while you sleep.

Cevacode is an autonomous engineering teammate that runs fully air-gapped on your own idle GPUs. Brief tasks at 6pm; review pull requests at 9am. The beachhead is a nightly autonomous security red-team — the one workload where nothing can leave your network.

● Nothing leaves the building Local open weights · Kimi K3 On-prem GPUs Nightly security scan
The problem

Two expensive things sit idle at the same time.

Your GPU cluster, 6pm → 9am

Enterprises run GPUs at ~5% utilization (Cast AI, 2026). A cluster that works 9-to-6 is dark all night and all weekend — depreciating whether it computes or not.

Work you can't send to the cloud

Regulated teams can't paste their stack into ChatGPT or a cloud agent. So the audits, upgrades, and refactors that need an AI never get done — policy forbids the tool.

How it works

Brief it. Leave. Wake up to pull requests.

Brief a task

“Audit the payments service for auth gaps and open PRs with fixes.” Queue it for tonight, or set it to run every night.

18:00 · you log off

Runs air-gapped, overnight

A local open-weight model (Kimi K3) drives the harness on your own idle GPUs. It reasons, edits, runs tests in a sandbox, and verifies fixes. Nothing leaves the network.

18:00–09:00 · on capacity you already own

Review pull requests

Each task lands as a reviewable PR with evidence attached — findings, repros, diffs, passing tests. You stay the operator: approve, don't type.

09:00 · a shift's work, done
Why air-gapped

The model runs on your hardware — not just the sandbox.

Cloud coding agents send your code out. “On-prem execution” tools still ship the reasoning to a vendor's cloud. For a bank or defense team, the sensitive part is the model inference itself. Cevacode runs it locally, so a security review has nothing to flag.

# managed cloud agent
code  → leaves your network
model → vendor cloud

# "on-prem execution" tools
code  → stays
model → still calls the cloud

# Cevacode
code  → stays
model → your idle GPUs
egress → none

Marginal cost to you is basically electricity. The idle capacity is already bought; Cevacode turns the hours you already paid for into engineering output.

What it does

Security is the beachhead. The night shift is the product.

Nightly security red-teambeachheadFind, reproduce, patch, validate — open a PR with the exploit and the fix.
Dependency upgradesBump, patch call-sites, run the suite, propose the diff.
RefactorsDead-code removal, dedupe, split god-files, migrate patterns.
Test generationRaise coverage on the thin spots; characterize legacy code.
Bug fixesSweep for real defects; open PRs with repros.
Private knowledge baseA verified, offline “Context7 + Stack Overflow” for your exact stack.
Who it's for

Teams that already own GPUs — and can't send code out.

Security vendorsExploit-grade code
Banks & tradingRegulated, audited
DefenseClassified, sovereign
InsurancePII-heavy, compliant
Landscape

Not another cloud agent.

The category is real and moving fast — open-source security harnesses like open·kritt prove the primitive and the demand. The open ground is running the model itself inside the customer's network, on a schedule, on hardware they already own.

 Code stays localModel runs on-premAir-gappedScheduled nightlyScope
Cloud coding agents
Copilot, Codex, Cursor
partialgeneral
Devin Outposts✗ cloud braingeneral
Kritt / open·kritt✓ self-host✗ BYO cloud modelon-demandsecurity
Cevacode✓ your GPUssecurity → general
Early access

Own idle GPUs and code you can't send out? Let's talk.

We reach out to design partners with idle on-prem GPU capacity first.