Skip to content

Security

See SECURITY.md for the full security model.

Key points

  • All ports bound to 127.0.0.1 (localhost only)
  • No data sent to any cloud service
  • Optional API key auth for REST endpoints
  • No telemetry, no tracking, no accounts
  • Embeddings computed locally via Ollama