Security
Your desktop and connected services
The desktop keeps your workspace and credentials on your device. Requests reach the model providers and tool services you choose.
This page states our product rules, not a release or attestation.
Architecture
The local desktop works without a muniment account. Your files, profile, and managed extensions live on your device.
Model requests go to configured providers. MCP servers contact their source services. Those services set their own data handling and account requirements.
Read the storage guide to find your workspace and managed packages.
Credentials
Your provider accounts stay on this device
muniment stores provider credentials locally. MCP bearer tokens use the system credential store. OAuth consent happens in your browser with the provider. Review the account and scopes before you authorize access.
Tools and files
Review what a tool can do
Installed plugins can execute code. A terminal command or connected tool can change files or remote data. Inspect packages and prompts before use. Stop cannot undo a completed action, and retry can repeat it.
Reply records
Inspect the reply and its actions
Replies expose model receipts and tool activity. Inspect changed files and sources before you rely on a result. A recorded action is evidence of what the tool reported, not a guarantee that its output is correct.
Mobile relay
Cloud availability is phase two
The phase-one desktop does not require a relay or cloud sign-in. Mobile access and cloud availability belong to phase two. Hidden cloud controls do not erase stored account data.
Cloud
Paid services are separate
Shared work, scheduled execution, and hosted routing form the paid cloud phase. The company record is optional and hidden by default. These services are not prerequisites for local desktop use.
Voice
Desktop voice stays on the device
The desktop voice stack processes speech on your device. Dictation places text in the composer. Sending that text passes it to the configured model provider. This rule does not cover mobile speech services.
Compliance
No unearned attestations
We claim no compliance attestation we do not hold. A local workspace does not make a connected provider or plugin compliant. Evaluate the services and permissions used for your work.
Disclosure
Responsible disclosure
Our disclosure policy sets the response time. We acknowledge reports within one business day. We do not pursue good-faith researchers.
Report a vulnerability security [at] muniment [dot] ai