Skip to content
Version 1.0.0

Lemniscate Documentation

The confined execution environment for code agents, deployed inside your perimeter.

Lemniscate provides the confined execution environment for code agents, deployed entirely inside your perimeter. The agent works in a sandbox with no network, no identity and no secrets, limited to a copy of the repository, under the control of the gateway services. The only thing that comes out is a code diff, which the developer reviews. No traffic leaves the perimeter (security white paper V3, section 1).

Three invariants hold whatever the model does (security white paper V3, section 1.2):

  • the agent cannot reach anything outside a perimeter defined in advance;
  • what it produces leaves through a single channel, subject to human review;
  • every action is attributable, logged and revocable.

The same product deploys in two ways. In both cases, it installs on your infrastructure or your customer’s, an isolated network is supported, and no traffic leaves.

A. Integrated with your stack

You keep your agent (OpenCode, an in-house tool), your model proxy (LiteLLM) and your inference engine. Lemniscate adds confined execution, policies, the log and revocation. Integrate Lemniscate with your stack.

B. Full code assistant

Where nothing is in place, Lemniscate also provides the extension (VS Code, JetBrains, terminal), the agent, the model access gateway and the setup of the inference server. Install the full assistant.

An agent can hand part of its work to a subagent, which runs in its own session, with its own guardrails, and returns a report. Delegate a task to a subagent gives the procedure; Delegating to subagents explains the rules that bound delegation.

This site contains two kinds of pages, and they do not promise the same thing.

The written pages (home, getting started, guides, explanations) describe the product as committed by the October 2026 security white paper V3. A page that restates a commitment from the white paper cites the relevant section. These pages describe a target: a guarantee described here may not yet be met by the version you install.

The reference pages are not written by hand: they are produced from the code, describe the code as shipped, and any discrepancy between a reference page and the code stops publication. When a reference page and a written page differ, the reference page states what the installed version does.

Each page declares the code closest to what it describes, and a check refuses to build the site when a page declares a file that no longer exists.

The documentation is frozen per version: the release notes state which one is current, and each published version stays readable at its own address.