Source: SPEC.md Section: Security trust model The desktop keeps local work and credentials on the user's machine. Model requests reach the providers the user configures. Voice processing is on-device. Published source makes the implementation inspectable. The desktop uses FSL-1.1-Apache-2.0. Each version converts to Apache 2.0 two years after its release. Public copy names the license and its conversion terms. Cloud availability belongs to phase two. The desktop hides Muniment sign-in and Account settings by default. Its independent company-record flag hides Record and Companies settings. These UI flags do not grant backend permissions. Provider sign-in and local routing remain available with both flags off. The company graph, when enabled, uses bounded reads and validated proposals. No public page promises a report or graph workflow before users can exercise it. Mobile pairing, relay encryption and hosted account tiers require release evidence before the site presents them as available. We claim no compliance attestation we do not hold. We acknowledge vulnerability reports within one business day. We do not pursue good-faith researchers.