Sometimes. An on-premises coding agent can keep prompts and code within your network if both the agent and model inference run there and the installation does not send data to external services. But “on-premises” alone is not a guarantee: a locally installed client may send context to a hosted model, while telemetry, integrations, or session syncing can create separate outbound connections.
What “on-premises” does—and does not—tell you
On-premises describes where some part of the software is deployed; it does not, by itself, specify where model inference happens or where every related data flow goes. Check the agent and the model separately. A server and model running inside your network can support local inference, but a client configured to use an external model API will send prompts and whatever context it includes to that provider.
Tabby illustrates the distinction. Its project describes a self-hosted, on-premises system and documents serving a model locally, showing that local inference is possible. That is not proof that every product marketed as on-premises uses local inference, or that every Tabby setup is offline. Tabby’s project documentation
Which data paths can leave the network?
Model prompts and code context
The inference endpoint is the first thing to identify. Find the exact hostname receiving requests and establish whether it belongs to a model server inside your network or an external provider. Also determine what the agent sends: the active selection, nearby files, repository excerpts, terminal output, screenshots, or conversation history may all be relevant depending on the product and configuration. There is no universal context rule that can be inferred from the label “coding agent.”
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Tabby’s privacy policy says completion prompts are sent from the device directly to the configured LLM provider using the user’s API key. In that configuration, the provider’s policies govern its handling of the prompts. Tabby privacy policy
Telemetry and diagnostics
Telemetry is a distinct flow from prompt or source-code content. Tabby’s IDE extension documentation says it collects aggregated anonymous usage data by default, including system and extension versions, completion counts, accepted completion counts, and HTTP request latency. The page says code and generated completions are not tracked or transmitted, and documents an opt-out setting. That inventory is dated November 6, 2023; check the settings and documentation for the release you deploy rather than assuming the same behavior today. Tabby IDE extension documentation
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Integrations, tools, and session history
An agent may contact other services independently of model inference. A source-control host, issue tracker, documentation index, package registry, search service, or remote tool can receive information needed for that integration. Session storage and synchronization are another separate path: prompts, responses, or session records may be uploaded for history, analytics, collaboration, or account sync.
For example, GitHub says locally run Copilot CLI and app sessions sync to an account by default, subject to available controls and enterprise policy. It says cloud-agent sessions run on GitHub and are shared by default with repository users. These behaviors concern Copilot, not all coding agents. GitHub Copilot session information
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
On-premises, regional cloud, and hosted inference are different boundaries
A provider’s regional data-residency control is not the same as processing entirely within a customer’s network. GitHub documents a Copilot data-residency option for GitHub Enterprise Cloud that keeps inference and associated data in a designated region. Its documentation inspected October 4, 2026, lists the United States and European Union as supported regions and says compatible clients are generally from 2025 onward. This describes a provider-region boundary, not an on-premises or air-gapped deployment. Availability can change. GitHub Copilot data residency
Cloud-service retention also depends on access surface and policy. GitHub’s Copilot privacy page says it does not use Copilot Business or Enterprise data to train its models. It states that IDE chat and code-completion prompts and suggestions are not retained by default; for other access and use, prompts and suggestions are retained for 28 days by default. User engagement data is retained for two years by default. These are GitHub-stated defaults inspected October 4, 2026, not guarantees for other plans, products, or future policy versions. GitHub Copilot data retention
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
How to check a specific deployment
Use these checks with the administrator or deployment owner. Vendor documentation describes intended behavior; configuration and observed traffic determine what a particular installation does.
- Identify the inference endpoint. Inspect the configured model and provider, then record the exact hostname the client contacts. Establish whether the model process and endpoint are inside your network, in a private cloud, or with an external provider.
- Inspect context controls. Determine which files, selections, repository excerpts, terminal output, screenshots, and prior messages can be sent. Check the product’s settings and documentation for the deployed version.
- Review telemetry and diagnostics. Find out whether usage statistics, crash reports, logs, or extension diagnostics leave the network; what fields they contain; who receives them; how long they are retained; and whether collection can be disabled.
- Inventory integrations and agent tools. List the hosted source-control, issue-tracking, documentation, package, search, and remote-tool services the workflow calls. Assess their data flows separately from model inference.
- Check history, sync, and sharing. Determine whether prompts, responses, or session records stay local, sync to an account, or become available to collaborators.
- Verify actual network behavior. Use network allowlists, DNS or proxy logs, or an isolated test environment to identify destinations contacted by the installed version. Compare observed traffic with the intended configuration.
Compare deployments by their data flows
| What to compare | What to establish |
|---|---|
| Inference location | Whether inference runs on a local server inside the network, in a private cloud, or through an external model provider. |
| Prompt and code path | Which data categories are sent, to what destination, and whether context includes repository content or tool output. |
| Telemetry | What fields are collected, who receives them, their retention period, and the available opt-out or policy controls. |
| Session and history path | Whether records are stored locally, synced to an account, stored in the cloud, or shared with others. |
| Network boundary | Whether data stays inside the customer’s network or within a provider’s designated region; those are different boundaries. |
| Verification | What product documentation, administrator settings, client version, and observed network destinations establish about the deployment. |
What to conclude before calling a setup private
“Self-hosted,” “on-premises,” and “private” are not substitutes for a deployment-specific data-flow check. A setup can keep inference local while still sending telemetry or syncing sessions; another can run its client locally but send prompts to a hosted model. Whether code or prompts leave your network depends on the exact endpoint, context configuration, integrations, session behavior, and network policy of the version in use.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




