Account authentication
Passwords are stored as derived hashes. Verification and password reset use expiring one-time links. Password changes and reset revoke sessions and device authorizations; local project records remain on the computer.
Device entitlement
The server checks verified email, paid subscription, active device count, and revocation when issuing or refreshing authorization. A desktop lease lasts at most five minutes. Each user may have one active device.
Desktop and local bridges
The desktop uses Electron context isolation, sandboxing, and a restricted preload interface. Its extension and MCP bridges bind to loopback and use random bearer tokens. MCP exposes only three read tools.
Protect the endpoint
The local SQLite workspace is not a substitute for full-disk encryption or operating-system access controls. Keep your computer updated, lock it when unattended, protect backup files, and do not paste secrets into context you plan to share.