AgentFormation is self-hosted in the operator's AWS account. The open-source project does not run a hosted service or receive deployment data.
The deployed system stores or processes:
- assigned employees' email addresses and federated Cognito identifiers;
- the mapping between an employee and an EC2 runtime;
- environment-creation status and AWS Step Functions execution history;
- short-lived request counters and upload claims in DynamoDB;
- encrypted runtime files on EBS;
- uploaded files in S3 until copied or expired;
- terminal tab labels in that browser's local storage until app sign-out; and
- normal AWS service, access, build, and application logs.
Each browser upload is limited to 50 MiB at the S3 write boundary, restricted to one random key and declared content type, copied to a server-owned sealed key before delivery, and deleted from staging after the runtime command finishes. The one-day bucket rule is a backstop if immediate cleanup cannot be confirmed.
Copying terminal text places it in the device's system clipboard. AgentFormation clears its own selection state after a successful copy, but browsers do not offer a safe, reliable way for a web app to erase the system clipboard later. Treat copied secrets like any other clipboard secret and replace them before sharing or leaving the device unattended.
The IAM Identity Center metadata address or downloaded XML contains
organization-specific SAML endpoints and public signing certificates. The
address belongs only in ignored agentformation.local.json; a fallback XML file
belongs in the ignored .agentformation/ directory. Neither should be committed
or posted publicly, even though the signing certificate is public and no private
signing key is included. The address is preferred because Cognito can refresh
updated metadata automatically.
Terminal traffic uses AWS Systems Manager. Prompts and code sent to Claude Code or Codex are processed through Amazon Bedrock under the operator's AWS agreement and configuration. Git providers, package registries, and any tools a user runs may receive additional data.
Codex uses Bedrock's OpenAI-compatible Responses API. That API can store response
state when a client requests it. The pinned Codex release sends store=false for
the built-in Bedrock provider, but maintainers should recheck this behavior before
upgrading Codex. See the Bedrock Responses API privacy notes
and the Codex source.
Operators are responsible for giving users appropriate notice, choosing AWS regions and retention settings, controlling log access, responding to data requests, and deleting users and resources when no longer needed. Do not use real personal or confidential data in a test deployment unless your policies allow it.