Toolradar Research
Coding assistants that uploaded the workspace
A dated incident log. In September 2026 Z.ai's ZCode was reported to package a local workspace, including git history, and upload it while the user was logged in. The 313 MB and 564-attempt figures are one developer's machine, not an industry total.

Founder, Toolradar & Dupple
Key findings
What the data shows.
- 01
Z.ai (also called Zhipu) disabled features of its coding assistant ZCode after developers reported that the desktop app uploaded local repositories without a clear ask. Reuters reported that on September 21, 2026. The South China Morning Post reported the same incident on September 20.
- 02
The concrete file sizes are one person's disk, not a Z.ai total. SCMP reported that a blogger, Ferstar, found a 313 megabyte encrypted archive pending upload after 564 failed attempts, and a 15 kilobyte file that had already been sent. The archive included a commercial project's git history. He could not open it. The private key, he said, sat on Z.ai's side.
- 03
Z.ai's account, as reported by Reuters: the behavior came from a Codebase Indexing feature that was on by default. The company apologized, said the data had been deleted, then said on Monday that some features were disabled. An assessment it attributed to a standards body affiliated with China's industry ministry, and to the security firm NSFOCUS, found the code data deleted and not retained on the cloud platform. Users told Reuters they could not independently confirm deletion, because the decryption key was not theirs.
- 04
Reuters also reported a company claim from Chengming Technology: six of its coding workspaces were uploaded, including source code, database passwords, and employees' personal information. That is Chengming's statement as carried by Reuters. It is not a count Toolradar made.
- 05
ZCode is not a Toolradar pick. We do not have a published listing for it, and this page does not rank it. The buyer page is best AI coding tools. The local-chat page is best private AI assistants.
About the research
How we built this report.
Toolradar tool database. Editorial review with weekly pricing verification.
2026. Snapshot taken September 21, 2026. Refresh due Oct 21, 2026.
Public scoring rubric. See how we rate for the full criteria.
Creative Commons BY 4.0. Quote, link, and reuse with attribution.
The log
| Date | Product | What was reported | What we will not say |
|---|---|---|---|
| September 18 to 21, 2026 | Z.ai ZCode | A logged-in desktop client packaged a local workspace, including git history, encrypted it with a server-supplied key, and uploaded it. SCMP and Reuters covered the apology, the default-on indexing feature, and the deletion claim. | That 564 is the number of customers affected. That figure is the failed retry count on one archive, as SCMP described Ferstar's machine. |
A second row gets added when a second product has a sourced incident of the same shape. A rumor, a benchmark, or a pricing change does not qualify.
What the two reports actually established
Ferstar's technical writeup, which SCMP and later Chinese coverage pointed at, describes a pipeline: the client asks Z.ai's coordinator for an upload signature and an RSA public key, archives the workspace locally, and posts the encrypted archive to Alibaba Cloud object storage. The private key is not on the laptop, so the user cannot read the file they just lost control of. The privacy policy, he wrote, talked about prompts submitted in conversation and did not describe a full-repo snapshot.
Reuters used different words for the destination ("overseas cloud servers") and led with the company's response. Both can be cited. We do not flatten them into one sentence that pretends we inspected the bucket.
The company's remedies, as reported, were: apologize, attribute the upload to default-on codebase indexing, say the objects were deleted, disable features, and point at a third-party assessment. The assessment is Z.ai's citation of CAICT-affiliated reviewers and NSFOCUS. We did not read that assessment. A vendor-commissioned "the bucket is empty" letter is a claim to put next to the incident, not a substitute for the incident.
The detail that matters for a buyer is the missing off switch. SCMP and the technical account say there was no control that stopped the snapshot while the user stayed logged in. A coding tool that can see the repo in order to autocomplete is not the same product as a coding tool that ships the repo to object storage before you ask.
What to do with a repo that cannot leave
Do not wait for a ranking of ZCode. It is not in this directory.
On best AI coding tools, the air-gapped option in the current shortlist is Tabnine. Cloud tools on that page, including Cursor, GitHub Copilot, and Claude Code, are ranked for capability. Their data-processing terms are not re-audited in this note. If the contract says code is excluded from training, that is a training promise. It is not a promise that a snapshot never hits object storage.
If the job is chat over files that must stay on the machine, use best private AI assistants and keep the cloud coding login out of that folder. Ollama on the machine is the default there. Logging a hosted assistant into the same directory throws the privacy ranking away, whatever the model card says.
What this log refuses to do
- It will not turn Ferstar's 313 megabytes or 564 failed attempts into a market statistic.
- It will not treat Chengming's "six workspaces" as a Toolradar census.
- It will not mark the deletion "verified" because the vendor said an auditor agreed. The users' objection, reported by Reuters, is that they could not open the ciphertext.
- It will not add a coding tool to best AI coding tools because it had an incident. The guide ranks tools a buyer can choose. This page ranks failures.
The next row needs a product name, a date, and a source that describes an upload the user did not order. Until then the log has one line, and that is the point.
Cite this report
Use the data, credit the source.
Released under Creative Commons BY 4.0. You may quote, link, and reuse the data with attribution.
More research
Software pricing changes we will not print yet
As of September 21, 2026 the Toolradar pricing tracker holds 536 proposed diffs and zero applied changes. 52 of those proposals share one copied before-state. This page does not quote a new list price from that queue.
Which stores block which AI shopping agents
A dated access log, not a ranking. As of September 21, 2026 Amazon blocks Meta Muse on Amazon.com. A Ninth Circuit order on August 4 vacated the injunction that had barred Perplexity Comet. Wizard's named native checkout is still Best Buy.
Which software categories are actually free
55% of the 10,656 published Toolradar tools offer a free path. That average hides a 75-point spread: Compliance is 17% free-path, Version Control is 92%. 21 dumped categories overlap, so this is a range, not one overlap-free mean.