Security

Your desktop and connected services

The desktop keeps your workspace and credentials on your device. Requests reach the model providers and tool services you choose.

This page states our product rules, not a release or attestation.

Architecture

The local desktop works without a muniment account. Your files, profile, and managed extensions live on your device.

Model requests go to configured providers. MCP servers contact their source services. Those services set their own data handling and account requirements.

Read the storage guide to find your workspace and managed packages.

Credentials

Your provider accounts stay on this device

muniment stores provider credentials locally. MCP bearer tokens use the system credential store. OAuth consent happens in your browser with the provider. Review the account and scopes before you authorize access.

Tools and files

Review what a tool can do

Installed plugins can execute code. A terminal command or connected tool can change files or remote data. Inspect packages and prompts before use. Stop cannot undo a completed action, and retry can repeat it.

Reply records

Inspect the reply and its actions

Replies expose model receipts and tool activity. Inspect changed files and sources before you rely on a result. A recorded action is evidence of what the tool reported, not a guarantee that its output is correct.

Mobile relay

Cloud availability is phase two

The phase-one desktop does not require a relay or cloud sign-in. Mobile access and cloud availability belong to phase two. Hidden cloud controls do not erase stored account data.

Cloud

Paid services are separate

Shared work, scheduled execution, and hosted routing form the paid cloud phase. The company record is optional and hidden by default. These services are not prerequisites for local desktop use.

Voice

Desktop voice stays on the device

The desktop voice stack processes speech on your device. Dictation places text in the composer. Sending that text passes it to the configured model provider. This rule does not cover mobile speech services.

Compliance

No unearned attestations

We claim no compliance attestation we do not hold. A local workspace does not make a connected provider or plugin compliant. Evaluate the services and permissions used for your work.

Disclosure

Responsible disclosure

Our disclosure policy sets the response time. We acknowledge reports within one business day. We do not pursue good-faith researchers.

security [at] muniment [dot] ai

Join the waitlist

Get desktop release updates.

We will email you about desktop releases and new features. muniment is a desktop workspace for your models, tools, and files.