What stays on your machine, what I read, and what never happens without you — for the CLI, the desktop app, devices and targets.

On this page

This page covers working on your own folders and machines. For builds from a brief, see Security & trust.

In one minute#

  • Your code stays on your machine, except what I read to do the work.
  • Your servers stay private. Targets' hosts, addresses and users never reach Ysra's servers.
  • Nothing is pushed or deleted without you.
  • Undo is exact.
  • Installs happen only with your OK, and only from verified sources.
STAYS ON YOUR COMPUTER REACHES YSRA Your folder and Git history worked on where they are The parts I read for a task and the output of commands I ran Keys, sign-ins, secret files never read What you ask me and my replies Where your targets are hosts, addresses, users A target's name and mode nothing about how to reach it Every approval decided on your computer A record of the work paths and checksums, not contents as needed name only
What stays on your computer, and the little that reaches Ysra to get the work done.

Your code#

I work on your folder where it is. It isn't copied or uploaded as a whole.

  • What leaves your machine: the parts of files I read to answer or make a change, and the output of commands I run for the task.
  • What doesn't: the rest of the folder, anything outside it, and files I'm not allowed to read.
  • Records of a piece of work keep paths, sizes and checksums. Not file contents.
  • Your prompts, code and data aren't used to train shared or public models.

Files I never read#

Environment files such as .env (examples like .env.example are fine), private keys and certificates, SSH and signing keys, package-registry sign-in files, and the credential folders of hosting and container tools.

Add your own patterns in .ysra/deny in the folder. See Keep more files from me.

Commands#

I run commands in a contained space on your machine:

  • writes only in the folder you opened and temporary space;
  • no network, except package registries while installing dependencies and the sites of a tool you've allowed;
  • no access to your keys, sign-ins, browser profiles or keychains;
  • no hardware (camera, GPU) and no Docker without your OK for that conversation.

If a machine can't contain commands, I don't run any there.

What never happens without you#

Action Rule
Push Always asks, every time. Never forced
Commit Only when you ask. Only the files I changed
Deleting a file Only files I created in the task. Anything else asks first
Deploy, publish, creating remote resources Always asks, with the exact command
Installing or starting a tool Always asks, showing exactly what runs
Docker, camera, GPU Asks once per conversation
Any change on a device or target Always asks
Signing in to anything Never. That's yours to do

Auto mode only skips questions about work inside your folder. It never answers anything in this table.

Things I don't do at all: force push, delete branches or tags, rewrite your history, run as root, type or store a password.

Undo#

Undo puts back exactly the files I changed, to exactly what they were. Files I created are removed. Your own edits are left alone. If I can't do that precisely (you've edited the files since, or they're committed), I refuse rather than guess.

I keep my own record of the work outside your folder, so your Git history is never touched to make this possible.

Installs#

  • The CLI download is checked against its published SHA-256 checksum before it is installed, and again on every ysra update.
  • Tools I install for you (Node.js, Python, Git) are official builds, checksum verified, placed in my own folder. Nothing system-wide.
  • Other tools go through your package manager or an official download with a checksum. No sudo, no password prompts.

Devices#

  • A device only connects out. No port is opened on it.
  • A device's sign-in can reach that device's work and nothing else: not your account, your balance, or other devices.
  • Devices start in observe mode.
  • Remove a device and it's signed out at once.

More: Devices.

Targets#

  • Targets are stored only on your computer, in a file only you can read.
  • Ysra's servers know a target's name, kind and mode. Never where it is or how to reach it. A breach on our side can't reveal your servers.
  • I use your SSH keys and your tool sign-ins where they already are. I never ask for or store a password or key.
  • The host key you confirmed is pinned. A different machine answering there is refused.
  • No port forwarding and no agent forwarding, so one target can't be used to reach others.
  • Each approval happens on your computer.
  • Secrets in output are removed before I see them; secret files are refused.
  • Text coming back from a target is data, never instructions.
  • Every command is logged on your computer with who approved it.

More: Targets.

Where things are kept#

What Where
Your sign-in Your operating system's keychain, or a file only you can read
Targets, logs, tools I installed ~/.ysra, readable only by you
Folders you've trusted Remembered as a checksum, not a readable path
My changes Your folder, until you commit, push or undo

Honest limits#

  • The Windows installer isn't signed yet, so Windows warns on first run.
  • Releases are verified by checksum. Release signatures aren't published yet.
  • Running commands needs macOS or Linux. On Windows I read and edit files.
  • What I read to do a task is sent to the model that does the work. If a file must never be read, add it to .ysra/deny.

Questions your security team has that this page doesn't answer: talk to us.

YsraDocs