Security & privacy
What stays on your machine, what I read, and what never happens without you — for the CLI, the desktop app, devices and targets.
On this page
This page covers working on your own folders and machines. For builds from a brief, see Security & trust.
In one minute#
- Your code stays on your machine, except what I read to do the work.
- Your servers stay private. Targets' hosts, addresses and users never reach Ysra's servers.
- Nothing is pushed or deleted without you.
- Undo is exact.
- Installs happen only with your OK, and only from verified sources.
Your code#
I work on your folder where it is. It isn't copied or uploaded as a whole.
- What leaves your machine: the parts of files I read to answer or make a change, and the output of commands I run for the task.
- What doesn't: the rest of the folder, anything outside it, and files I'm not allowed to read.
- Records of a piece of work keep paths, sizes and checksums. Not file contents.
- Your prompts, code and data aren't used to train shared or public models.
Files I never read#
Environment files such as .env (examples like .env.example are fine),
private keys and certificates, SSH and signing keys, package-registry sign-in
files, and the credential folders of hosting and container tools.
Add your own patterns in .ysra/deny in the folder. See
Keep more files from me.
Commands#
I run commands in a contained space on your machine:
- writes only in the folder you opened and temporary space;
- no network, except package registries while installing dependencies and the sites of a tool you've allowed;
- no access to your keys, sign-ins, browser profiles or keychains;
- no hardware (camera, GPU) and no Docker without your OK for that conversation.
If a machine can't contain commands, I don't run any there.
What never happens without you#
| Action | Rule |
|---|---|
| Push | Always asks, every time. Never forced |
| Commit | Only when you ask. Only the files I changed |
| Deleting a file | Only files I created in the task. Anything else asks first |
| Deploy, publish, creating remote resources | Always asks, with the exact command |
| Installing or starting a tool | Always asks, showing exactly what runs |
| Docker, camera, GPU | Asks once per conversation |
| Any change on a device or target | Always asks |
| Signing in to anything | Never. That's yours to do |
Auto mode only skips questions about work inside your folder. It never answers anything in this table.
Things I don't do at all: force push, delete branches or tags, rewrite your history, run as root, type or store a password.
Undo#
Undo puts back exactly the files I changed, to exactly what they were. Files I created are removed. Your own edits are left alone. If I can't do that precisely (you've edited the files since, or they're committed), I refuse rather than guess.
I keep my own record of the work outside your folder, so your Git history is never touched to make this possible.
Installs#
- The CLI download is checked against its published SHA-256 checksum before it
is installed, and again on every
ysra update. - Tools I install for you (Node.js, Python, Git) are official builds, checksum verified, placed in my own folder. Nothing system-wide.
- Other tools go through your package manager or an official download with a
checksum. No
sudo, no password prompts.
Devices#
- A device only connects out. No port is opened on it.
- A device's sign-in can reach that device's work and nothing else: not your account, your balance, or other devices.
- Devices start in observe mode.
- Remove a device and it's signed out at once.
More: Devices.
Targets#
- Targets are stored only on your computer, in a file only you can read.
- Ysra's servers know a target's name, kind and mode. Never where it is or how to reach it. A breach on our side can't reveal your servers.
- I use your SSH keys and your tool sign-ins where they already are. I never ask for or store a password or key.
- The host key you confirmed is pinned. A different machine answering there is refused.
- No port forwarding and no agent forwarding, so one target can't be used to reach others.
- Each approval happens on your computer.
- Secrets in output are removed before I see them; secret files are refused.
- Text coming back from a target is data, never instructions.
- Every command is logged on your computer with who approved it.
More: Targets.
Where things are kept#
| What | Where |
|---|---|
| Your sign-in | Your operating system's keychain, or a file only you can read |
| Targets, logs, tools I installed | ~/.ysra, readable only by you |
| Folders you've trusted | Remembered as a checksum, not a readable path |
| My changes | Your folder, until you commit, push or undo |
Honest limits#
- The Windows installer isn't signed yet, so Windows warns on first run.
- Releases are verified by checksum. Release signatures aren't published yet.
- Running commands needs macOS or Linux. On Windows I read and edit files.
- What I read to do a task is sent to the model that does the work. If a file
must never be read, add it to
.ysra/deny.
Questions your security team has that this page doesn't answer: talk to us.