Intelligible — the team behind elbi — is part of TechCrunch Disrupt's 2026 Startup Battlefield 200
elbi

Security

Nothing leaves your network unless you point it there.

elbi’s trust model starts with running locally and being readable end to end, then adds the gates a trustworthy answer needs.

01

Local by default

elbi runs as a process on your machine — no account, no sign-in. Nothing reaches the network unless a step you configured needs to: a model call, a warehouse connection you set up.

02

Open enough to audit

The SDK, CLI, agent runtime, MCP server, and web app are Apache-2.0 — every verification gate included. Read the source instead of taking our word for it.

03

Gates run before serving

A data contract — types, ranges, keys, referential integrity — is checked before a derivation's output serves. Agent-authored ones run under isolation and need a named human's certification first.

04

Enterprise identity, built on standards

elbi-enterprise adds OIDC single sign-on, sender-constrained tokens (RFC 9449 DPoP) and PKCE instead of bearer tokens alone, plus row- and column-level policy and SCIM sync.

Responsible disclosure

Found a vulnerability? Tell us privately.

Report it through our security policy, not a public issue. We’ll acknowledge it and work with you on a fix and a timeline.

Enterprise

Need SSO, per-object policy, or a compliance review?

elbi-enterprise deploys on your own Kubernetes cluster via Helm, or through Terraform on AWS, Azure, or GCP.