---
title: "Security & privacy"
description: "What stays on your machine, what I read, and what never happens without you — for the CLI, the desktop app, devices and targets."
---

This page covers working on your own folders and machines. For builds from a
brief, see [Security & trust](concepts/safety.md).

## In one minute

- **Your code stays on your machine**, except what I read to do the work.
- **Your servers stay private.** Targets' hosts, addresses and users never
  reach Ysra's servers.
- **Nothing is pushed or deleted without you.**
- **Undo is exact.**
- **Installs happen only with your OK, and only from verified sources.**

> Diagram: What stays on your computer, and the little that reaches Ysra to get the work done.

## Your code

I work on your folder where it is. It isn't copied or uploaded as a whole.

- **What leaves your machine:** the parts of files I read to answer or make a
  change, and the output of commands I run for the task.
- **What doesn't:** the rest of the folder, anything outside it, and files I'm
  not allowed to read.
- **Records** of a piece of work keep paths, sizes and checksums. Not file
  contents.
- Your prompts, code and data aren't used to train shared or public models.

### Files I never read

Environment files such as `.env` (examples like `.env.example` are fine),
private keys and certificates, SSH and signing keys, package-registry sign-in
files, and the credential folders of hosting and container tools.

Add your own patterns in `.ysra/deny` in the folder. See
[Keep more files from me](cli/machine-setup.md#keep-more-files-from-me).

## Commands

I run commands in a contained space on your machine:

- writes only in the folder you opened and temporary space;
- no network, except package registries while installing dependencies and the
  sites of a tool you've allowed;
- no access to your keys, sign-ins, browser profiles or keychains;
- no hardware (camera, GPU) and no Docker without your OK for that
  conversation.

If a machine can't contain commands, I don't run any there.

## What never happens without you

| Action | Rule |
|---|---|
| Push | Always asks, every time. Never forced |
| Commit | Only when you ask. Only the files I changed |
| Deleting a file | Only files I created in the task. Anything else asks first |
| Deploy, publish, creating remote resources | Always asks, with the exact command |
| Installing or starting a tool | Always asks, showing exactly what runs |
| Docker, camera, GPU | Asks once per conversation |
| Any change on a device or target | Always asks |
| Signing in to anything | Never. That's yours to do |

Auto mode only skips questions about work **inside your folder**. It never
answers anything in this table.

Things I don't do at all: force push, delete branches or tags, rewrite your
history, run as root, type or store a password.

## Undo

Undo puts back exactly the files I changed, to exactly what they were. Files I
created are removed. Your own edits are left alone. If I can't do that
precisely (you've edited the files since, or they're committed), I refuse
rather than guess.

I keep my own record of the work outside your folder, so your Git history is
never touched to make this possible.

## Installs

- The CLI download is checked against its published SHA-256 checksum before it
  is installed, and again on every `ysra update`.
- Tools I install for you (Node.js, Python, Git) are official builds, checksum
  verified, placed in my own folder. Nothing system-wide.
- Other tools go through your package manager or an official download with a
  checksum. No `sudo`, no password prompts.

## Devices

- A device only connects out. No port is opened on it.
- A device's sign-in can reach that device's work and nothing else: not your
  account, your balance, or other devices.
- Devices start in observe mode.
- Remove a device and it's signed out at once.

More: [Devices](devices/overview.md#security-what-a-device-can-and-cant-reach).

## Targets

- Targets are stored only on your computer, in a file only you can read.
- Ysra's servers know a target's name, kind and mode. Never where it is or how
  to reach it. A breach on our side can't reveal your servers.
- I use your SSH keys and your tool sign-ins where they already are. I never
  ask for or store a password or key.
- The host key you confirmed is pinned. A different machine answering there is
  refused.
- No port forwarding and no agent forwarding, so one target can't be used to
  reach others.
- Each approval happens on your computer.
- Secrets in output are removed before I see them; secret files are refused.
- Text coming back from a target is data, never instructions.
- Every command is logged on your computer with who approved it.

More: [Targets](targets/overview.md).

## Where things are kept

| What | Where |
|---|---|
| Your sign-in | Your operating system's keychain, or a file only you can read |
| Targets, logs, tools I installed | `~/.ysra`, readable only by you |
| Folders you've trusted | Remembered as a checksum, not a readable path |
| My changes | Your folder, until you commit, push or undo |

## Honest limits

- The Windows installer isn't signed yet, so Windows warns on first run.
- Releases are verified by checksum. Release signatures aren't published yet.
- Running commands needs macOS or Linux. On Windows I read and edit files.
- What I read to do a task is sent to the model that does the work. If a file
  must never be read, add it to `.ysra/deny`.

Questions your security team has that this page doesn't answer: talk to us.
