Graded C- on resilience. In Vannus's assessment it runs no foundation model at all — acceptable, with limits worth knowing.
Local-first proxy that masks secrets and proprietary identifiers in code before a developer's prompt reaches an AI coding tool, and restores them when the response returns.
No foundation model. Pretense does not run one, so this criterion does not apply and is excluded from the grade rather than counted against it. A local proxy that masks identifiers before a prompt reaches an AI coding tool and restores them on the way back. The masking is deterministic hashing, not inference, and the model that answers is whichever one the customer already uses. Reviewed from the vendor’s own documentation: pretense.ai ↗ If that is out of date, tell us at right of reply.
Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.
This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.
On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.
The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.
Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →