Plans and trust
What Rehearsal touches, where your keys and data are, what each plan allows, and what is not built yet.
These pages are for the person who must approve Rehearsal: a security reviewer, a buyer, or a team lead. They say what the product does and does not do, with nothing left for a sales call.
Security and trustWhat a world can reach, how checks stay read-only, and where keys are kept.Plans and limitsWhat each hosted plan allows, generated from the table the server enforces.What costs moneyThe four actions that spend model budget, and the limits.Not built yetFeatures that are planned and not in this version.
The short answers
| Question | Answer |
|---|---|
| Does Rehearsal touch our production systems? | No. It builds a world from your source and images, in a sandbox, with fictional data it creates. It does not connect to production |
| Can a world reach the internet? | No. The application's containers are on a network with no way out |
| Who decides whether an agent passed? | Read-only queries on the application's own database. No model grades the result |
| Can a check change data? | No. A check is one statement in a read-only transaction |
| Where is our API key? | The server stores only a hash. The key is shown once |
| Where are the model provider keys? | On the server only. On the hosted service you need none. On your own server they are in its settings |
| Can we run it ourselves? | Yes. The same package runs on your own machine: see Self-hosting |
| Can an AI assistant spend without asking? | The plugin tells it to ask first. The plan's limits are a hard stop either way |
Checked against rehearsal-kit 0.1.2 on 11 October 2026.
Was this page helpful?
Troubleshooting
Each message you can meet when you install and run a Rehearsal server, why it appears, and the fix. Search this page for the exact message.
Security and trust
What a practice world can and cannot reach, how checks stay read-only, where keys and passwords are kept, and what an operator must do.