Two extractive encoder models run inside the process, pinned by revision, which locks them to one version, plus two embedding models for classification. Three generative models run through a local Ollama, pinned by digest, a checksum, and optional. On your own file, measure:yours measures the two extractive tiers by default. It adds your regexes as a tier at zero cost when you pass --rules, and the three generative tiers when you pass --llm. Up to six tiers are measured. The human tier is an assumption until you measure it, which measure:humans does on your own reviewers. The only network call on the measurement path goes to the generative host, and the tool checks that it is local immediately before each call. Pointed at a remote machine, it will not start unless you pass the override flag yourself.
An egress run samples the open connections during a pass, and its file is published. One whole pass on client cases showed 0 connections over 21 samples. The file records its own limit. Sampling can miss a connection between two samples, so the count is a floor. There is no capture at kernel level.
Watch it runThe egress command samples the open connections during a pass, then publishes the hosts it saw and whether any connection went out.
run it yourself
npm run egresswatches the pass, and the committed file shows 0 connections
Where it livessrc/tiers.ts:556 · egress.json:12