Earlier quoted context omitted.
> 2: The code your are writing is subject to regulatory control. Can you expand on what, precisely, you mean by that?
If I remember correctly, certain regulatory environments require that an audit log be kept of who saw which file and when.
Okay, let's say that's your environment. How do you prevent Mole Manny (who is a legit developer in your organization) from pulling down all the files in his project (as he's entitled to do), and then copying it over to his $super_sneeky_storage_system?
We've talked a lot about this where I am and we've concluded that to ensure a super-tight environment we'd have to do a slew of really heinous lockdowns (epoxy usb ports for instance) which would likely not really do much against moles but slow down and anger legit users.