Security starts with a clear boundary

This is an architectural overview, not a compliance certification or production security guarantee.

Explicit placement
Projects run on their host computer. Sharing is opt-in and requires the host to be available.
Scoped membership
The host approves each device and controls its access to project threads, files, tools, and previews.
Trusted execution
Project APIs are scoped, but executable code runs with the host user's privileges. This is not an operating-system sandbox.
Your AI connections
Each participant uses their own locally stored provider connection. Provider credentials stay on that participant's computer; model usage follows the provider's terms.
Back to Worktree