Security, privacy and release integrity

No cloud account, no traffic relayYour key goes straight to the provider you picked. Configuration and backups stay on your machine. No application telemetry is collected by default.

Your data stays on your device

The interface and the API both run on a loopback address. Configuration, backups and state are written on your machine.

The local service is not a control plane for anything outside it.

A key only goes where it has to

An API key is written to the one file the target agent needs to work: its own configuration, or BootAgent's environment file.

Keys never appear in the BootAgent profile, logs, screenshots, web analytics events, or command-line arguments.

Where it lands depends on the agent and the operating system. These are the common ones:

  • ~/.codex/config.toml
  • ~/.claude/settings.json
  • ~/.config/opencode/opencode.jsonc
  • ~/.config/kilo/kilo.jsonc
  • ~/.bootagent/

The launcher lists the real paths before and after every write.

A backup comes before any change

Before modifying existing configuration, BootAgent writes a timestamped backup.

Configuration directories and files holding a key are readable only by the current user. The cleanroom check confirms the real user directory was untouched by the test run.

Every channel ships the same package

The GitHub Releases this site points at and the Gitee mirror for mainland-China networks distribute the identical official build. For a given version, the contents and checksums match.

Channels do not repackage, append promotional content, or re-sign.

Third-party agent binaries are not redistributed by BootAgent. They come from the official installer, a mirror with written permission, or your own manual install.

Current release evidence

These states come from the published release metadata on GitHub Releases; the version and each artifact's checksum are stated on the current release page itself.

  • Channel: technical-preview
  • Platform: macOS Apple silicon / ARM64
  • macOS signing: Developer ID-signed and notarised by Apple, ticket stapled. The signing identity's Team ID is F2VC757B28.
  • Windows signing: Authenticode is not done yet, which is why the release as a whole is still not stable.

You can verify the macOS signature yourself once installed:

spctl -a -vv -t exec /Applications/BootAgent.app

Expect accepted with source Notarized Developer ID, and the signer's Team ID matching the one above.

Whether the build was native, and whether a cleanroom run passed, is recorded by the release process — this page does not assert it on the release process's behalf.

The stable gate

Each platform reaches stable on its own once it qualifies, without waiting for the others.

  • macOS: Developer ID signature, notarisation, stapled ticket — met since v0.7.0
  • Windows: a valid Authenticode signature
  • Every platform: a native build and cleanroom evidence

Explicitly out of scope

These are not part of the product, and will not be added as features:

  • VPNs, proxy nodes, or instructions for getting around network restrictions
  • Shared API keys, a unified model gateway, reselling models or API access
  • Unauthorised agent binaries and channel-customised packages
  • Describing a technical preview as stable or as security-certified