Fuzit
Trust Architecture

Your repository stays
under your control.

Fuzit is local-first repository intelligence. Core indexing, static analysis, graph construction, ranking and context packaging operate on your machine. Remote access occurs only through explicit provider workflows.

Know what stays local. Know what crosses a boundary. Know why.

Local Machine Boundary
Repository
Discovery / Scan
Incremental Index
Analysis / Graph
Security Filtering
Selection / Packaging
CLI / MCP / VS Code / Plugin Host
GitHub ProviderExplicit Remote Request

Local-first, not mysteriously offline

Fuzit does not require a cloud service to process your codebase. Ordinary local repository workflows do not require repository upload. The core intelligence engine—discovery, scanning, indexing, analysis, graph construction, and ranking—runs entirely on your machine.
Verified Operating Constraints
Execution Environment
Runs locally
Tracking
No telemetry
Infrastructure
No cloud required
Source Privacy
No repository upload
Model Lock-in
AI agnostic

Analyze the repository. Don't run it.

Repository intelligence is based on static evidence. Fuzit extracts normalized framework and language signals without requiring arbitrary project execution.

Source Files
PARSE / ANALYZE
Normalized Evidence
Build Scripts
Execute Project

Secrets should not become context.

Security filtering is part of the core context pipeline—not an afterthought after model delivery. Fuzit applies redaction policies for known sensitive paths, tokens, and API keys before they can gain relevance simply because a task mentions them.
Pipeline Execution
src/auth/session.tsCandidate
.env.localSensitive Path Detected
Security Filter Applied
Context Output
src/auth/session.ts
.env.localBlocked / Omitted

Network access should be explicit.

Ordinary local commands do not silently become network operations. Remote provider functionality is invoked exclusively through explicit provider workflows.

Explicit Workflows

  • Direct GitHub URL processing (fuzit context https://...)
  • PR review evidence (fuzit review / fuzit pr)
  • Issue extraction (fuzit issue)
  • Explicit provider targeting (provider github)
NETWORK BOUNDARY
LOCAL FUZIT ENGINE
User invokes fuzit review
Normalized remote evidence
GitHub Provider

Authentication & Offline Resilience

GitHub provider access uses standard environment tokens, falling back to anonymous use where possible. Tokens should not be supplied through unsafe token-bearing URLs or CLI arguments.
Remote Provider Rules
Token Precedence
FUZIT_GITHUB_TOKEN → GH_TOKEN → Anonymous
URL Safety
Tokens are not permitted in URLs
Cache Semantics
Offline reuse of previously acquired metadata
Resilience
Provider failure does not invalidate local evidence

Surfaces & Isolation

Fuzit exposes intelligence through explicitly bounded service surfaces.

MCP Trust Surface

MCP exposes Fuzit's local context services to compatible clients. The server is strictly read-only, local, and stdio-based. It does not provide arbitrary repository execution or unrestricted filesystem tools.

AI CLIENT
⇅ Stdio
READ-ONLY FUZIT MCP
↓
CANONICAL LOCAL ENGINE

Plugin Host

Fuzit runs extensions via a restricted, out-of-process plugin host. Filesystem, network, shell, and runtime access are denied by default.

PLUGIN
↓ Restricted Interface
PLUGIN HOST PROCESS
↓ Approved Service Boundary
FUZIT ENGINE

Editor & Watcher

The VS Code extension consumes the same canonical local engine. It strictly respects Workspace Trust enforcement.

The local watcher operates purely for filesystem observation to maintain incremental freshness, with no hidden network behavior.

Same Local Engine

Context should have a trail.

Fuzit prepares context before downstream AI consumption in an AI-agnostic model. Users can inspect exactly what was selected, why it was included, what was omitted, and where the evidence originated.
EvidenceSourceDecisionReason
src/auth/session.tsLocal repoIncludedTask + symbol relationship
.env.localLocal repoExcludedSecurity policy

Master Trust Ledger

A definitive breakdown of Fuzit's behavior and control boundaries.

ConcernFuzit BehaviorControl Boundary
Repository PrivacyCore intelligence runs locally. Does not require uploading the repository to a Fuzit cloud service.Local Machine
SecretsTokens, keys, and sensitive paths are filtered before they can become context output.Pre-output Policy
Network AccessOrdinary local commands do not silently contact remote endpoints.Explicit Invocation
Repository ExecutionAnalysis is derived statically. Fuzit does not run build scripts or application code.Static Evidence
MCP ServerExposes intelligence over local stdio. Read-only by default.Bounded Schema
PluginsExtensions execute externally over a restricted interface, with capabilities denied by default.Out-of-process
TelemetryNo background telemetry or analytics collection.None
What Fuzit Does Not Require
  • A Fuzit cloud account
  • Repository upload
  • Background telemetry
  • Execution of your code