Three Steps, Then Push as Usual
Make a team
Sign in with GitHub, create a team, and add each repository whose replays you want to protect. Each one gets its own key.
Commit one line
Add the repository's project id to .ccc/map.json. From then on, ccc encrypts every replay it saves before it's pushed.
Invite the team
Invite people by GitHub username. After they join and run ccc login, replays open in the visualiser as before.
Prompts and Plans Stay With the Team
A replay holds the asks, the agent's plan and every edit along the way. Anyone who can read the repository can read the replay, unless it's encrypted.
Encrypted before it's pushed
ccc encrypts each replay on your machine with the repository's key, using age. Your git host stores only the encrypted copy.
Access follows the team
ccc asks Runccc to unlock each replay it opens, and Runccc checks you're on the team every time. Remove someone and they can't open any replay, old or new. You can see who has opened each repository's replays.
No keys on laptops
A repository's private key never leaves Runccc, so a lost laptop or a departed teammate takes no keys with them. ccc is open source, so you can read exactly what it sends.
We never see a replay
Replays live in your git remote, beside your branches. Runccc holds the keys but never receives a replay, and your git host holds the replays but no keys, so neither can read them alone.
Start Free, Pay as You Grow
Free
$0
- One team
- One repository
- As many members as you like
Each further team
$30/month
For a second client, department or open source project, each with its own members.
Each further repository
$5/month
Every repository has its own key, so you can remove one without touching the rest.
Billed monthly through Stripe to the team's owner. Cancel any time: an unpaid repository's replays stay safe in your git remote, and open again when it's paid for.
Ready When Your Team Is
Sign in, make a team, and the next replay you push is encrypted.
Sign in with GitHub