Skip to content
Early access Kaleidoscope needs a key to run. Email contact@kleosresearch.xyz and we will send you one.

Security

The engine ships as object code rather than source. That is a distribution choice, not a security guarantee: a native binary on your machine is still inspectable.

The engine keeps your memory in a local vault, speaks stdio to your editor, and makes no external model calls. It needs the network for one thing, the licence check: after about 20 minutes without a successful check, mcp and call refuse to run.

The manager starts it with a closed, non-secret environment rather than passing along yours. Your model-provider keys, account tokens, cloud credentials and the vault’s location are not in what the engine process receives.

Account commands never touch the memory engine. The manager can reach eleven account routes and no others, and a guard rejects memory fields, profile fields and absolute local paths before anything is sent.

There is no account service to reach in any case: all eleven refuse with provider not configured, before anything local is opened. The commands belong to a second program that is published on no channel — see account commands.

There is no Apple signing and no notarisation, and the native code is ad-hoc signed only. Nothing here lets you verify that a file you received is the file we built. Production trust roots and signing identities do not exist yet.

You meet this on macOS first. An unsigned program has no stable identity for the operating system to remember, so a credential prompt can come back every launch — which is why the account page says a Keychain approval may not stick.

We put distinctive marker values into the environment, the profiles, the editor configuration and the MCP traffic, then check that none of them turn up in output. It runs on macOS with Apple Silicon, and it finds only the kinds of leak it was written to look for.

Do not put an exploit or a sensitive report in a public issue.

Email contact@kleosresearch.xyz with Security in the subject line.

No security policy is in force yet, so nothing commits us to a response time or to which versions get a fix. The review draft says what those commitments will be.