Security

Local-first by design.

Secrets, policies, and audit data never leave your machine. The cloud is only licensing, updates, and opt-in telemetry.

Where your data lives

On your disk, in your keychain.

Everything that describes your work and your access stays on the machine that runs it.

  • Audit data lives in local storage, never a shared cloud.
  • Secrets sit in the OS keychain — zero plaintext API keys on disk.
Keychain / secrets view or a policy profile
The governed gateway

Default-deny, per host.

  • Destructive actions are denied by default until approved.
  • Per-host access tokens — each AI app sees only what you granted.
  • Sandbox mode to try a new server before you trust it.
The audit ledger

Tamper-evident by construction.

  • Append-only and hash-chained — nothing edits quietly.
  • Exportable with an integrity proof for a security review.
  • Tool outputs tagged and prompt-injection flagged.
Licensing & telemetry

Works air-gapped.

  • Offline-verifiable Ed25519 licence keys — paid features work air-gapped.
  • Telemetry off by default, content-free, public schema.

Control you can prove, on hardware you own.

Download for macOS
Work with AI that works with you.