Local-first architecture
No server-side components, no cloud storage, no remote endpoints. The attack surface is limited to your local machine.
Our security architecture, responsible disclosure process, and the practices we follow to keep your local AI workspace safe.
No server-side components, no cloud storage, no remote endpoints. The attack surface is limited to your local machine.
Connector tokens and secrets are stored in macOS Keychain or Windows Credential Manager. Never in plaintext.
Downloaded models are verified by SHA-256 checksum. Tampered files are rejected before loading.
Every line of code is open for inspection. Security researchers can audit our implementation at any time.
Automated dependency scanning with Dependabot. Critical vulnerabilities are patched within 24 hours.
We reward responsible disclosure. Critical vulnerabilities earn up to $5,000. See our security.txt for details.
Reach our security team at security@gotchi.ai for our detailed whitepaper.