Security
The engine ships as object code rather than source. That is a distribution choice, not a security guarantee: a native binary on your machine is still inspectable.
What the engine can reach
Section titled “What the engine can reach”The engine keeps your memory in a local vault, speaks stdio to your editor, and
makes no external model calls. It needs the network for one thing, the
licence check: after about 20 minutes
without a successful check, mcp and call refuse to run.
The manager starts it with a closed, non-secret environment rather than passing along yours. Your model-provider keys, account tokens, cloud credentials and the vault’s location are not in what the engine process receives.
What account commands can send
Section titled “What account commands can send”Account commands never touch the memory engine. The manager can reach eleven account routes and no others, and a guard rejects memory fields, profile fields and absolute local paths before anything is sent.
There is no account service to reach in any case: all eleven refuse with
provider not configured, before anything local is opened. The commands belong
to a second program that is published on no channel — see
account commands.
Nothing is signed for production
Section titled “Nothing is signed for production”There is no Apple signing and no notarisation, and the native code is ad-hoc signed only. Nothing here lets you verify that a file you received is the file we built. Production trust roots and signing identities do not exist yet.
You meet this on macOS first. An unsigned program has no stable identity for the operating system to remember, so a credential prompt can come back every launch — which is why the account page says a Keychain approval may not stick.
What we check for leaks
Section titled “What we check for leaks”We put distinctive marker values into the environment, the profiles, the editor configuration and the MCP traffic, then check that none of them turn up in output. It runs on macOS with Apple Silicon, and it finds only the kinds of leak it was written to look for.
Report a vulnerability
Section titled “Report a vulnerability”Do not put an exploit or a sensitive report in a public issue.
Email contact@kleosresearch.xyz with
Security in the subject line.
No security policy is in force yet, so nothing commits us to a response time or to which versions get a fix. The review draft says what those commitments will be.