Run Baz in your own environment

Bring agentic code review and coding agents to your team without your source code ever leaving your infrastructure. Choose Private Mode to keep your codebase in your VPC, or self-host the entire Baz cluster.

Customer-Hosted Cluster
Ingress Rules
Traefik Controller
Your Code
File System Service Pod
BAZ PRIVATE MODE
Baz Hosted On AWS EKS
Baz Workers
Background Agents
Rest API
Baz
Web, CLI, MCP

Your code, your infrastructure, your audit trail

Two ways to run Baz, both built on the same controls. See the Private Mode and security & compliance docs for the full picture.

Private Mode

Deploy one File System Service pod inside your VPC. Baz gets scoped, temporary read access per review and wipes the code the moment it finishes.

Read the Private Mode guide

Self-hosted cluster

Run the entire Baz control plane and agent runtime in your own cloud, for full control over isolation and data residency.

Talk to sales

Scoped, transient access

Baz reads only the repos you onboard, contents: read and nothing more. Code is held for analysis and wiped when the review ends, never persisted on Baz servers.

Authenticated, isolated connectivity

The FSS pod sits behind your ingress and talks to Baz over a hardened REST channel: IP allowlisting, TLS, and API-key auth. Only Baz's published IPs can reach it.

Least-privilege agents

Agents inherit your repo permissions, branch protection, and policy rules. They never act outside the scope you grant.

Selective write

Auto-fix, auto-approve, and auto-merge are gated by labels, allowlists, and protected branches, so automation acts only where you allow it.

Tamper-evident audit logs

Every FSS operation is logged inside your environment with cryptographically traceable records, so every automated action stays reviewable.

Reversible by default

Automated actions are reversible, with global kill switches. If the FSS goes offline, reviews pause and resume automatically.

Built for security reviews, ready when you are

Baz is SOC 2 certified and runs in isolated AWS environments. Infrastructure is code, version-controlled, and deployed through authenticated CI/CD, so every change leaves an auditable trail.