Gotchi
Security

Security at Gotchi

Our security architecture, responsible disclosure process, and the practices we follow to keep your local AI workspace safe.

Security practices

Local-first architecture

No server-side components, no cloud storage, no remote endpoints. The attack surface is limited to your local machine.

OS-level credential storage

Connector tokens and secrets are stored in macOS Keychain or Windows Credential Manager. Never in plaintext.

Model verification

Downloaded models are verified by SHA-256 checksum. Tampered files are rejected before loading.

Open-source transparency

Every line of code is open for inspection. Security researchers can audit our implementation at any time.

Dependency auditing

Automated dependency scanning with Dependabot. Critical vulnerabilities are patched within 24 hours.

Bug bounty program

We reward responsible disclosure. Critical vulnerabilities earn up to $5,000. See our security.txt for details.

Responsible disclosure

Found a vulnerability?

Report security issues to security@gotchi.ai. Please include a detailed description, steps to reproduce, and potential impact. We acknowledge reports within 24 hours and aim to resolve critical issues within 72 hours. We do not take legal action against researchers who follow responsible disclosure practices.
Data boundary
Conversations
Documents
Embeddings
0 bytes sent to the cloud

Questions about security?

Reach our security team at security@gotchi.ai for our detailed whitepaper.

macOS·Windows·No telemetry·Free core · €49.99/yr all-in · Free updates