Skip to content

Security & privacy

Secure by construction.
Not by promise.

Pogama's safety comes from how it's built: what the interface can't do, it can't be tricked into doing. Here is exactly how — and where data does leave your computer.

Local-first

Your workspace lives on your computer.
Stored locally
Projects, chats, history, settings, captures and recordings.
Leaves your computer
What you send to the model provider you chose — messages, and files after you confirm sending them to a cloud model.
Optional account
Team tasks, licenses and Client Hub sync. Client credentials are encrypted on your device before they sync.
Usage facts
Feature counts and errors, never content, prompts, files, paths or keys. Turn them off in Settings → Privacy.

Credential storage

Keys live where your operating system keeps secrets.
OS credential store
Windows Credential Manager (Keychain on macOS, Secret Service on Linux).
Write-only from the UI
The interface can save a key but there is no command to read it back.
Host-bound
A key is attached by the native backend only to requests for the host it was saved for; changing the endpoint invalidates it.
Never in logs
Keys, bearer tokens and secret-looking values are redacted from every log.

AI provider boundaries

The model sees what you send it — nothing more.
Through a native proxy
Provider traffic goes through Pogama's Rust backend, which adds the key; the webview never holds it.
Local or cloud, visible
The message box says whether a model is local or in the cloud, and asks before files go to the cloud.
Untrusted output
Model output is treated as untrusted: rendered without raw HTML, never executed without your permission.

File & terminal access

Only the folders you open, only with your say.
Granted folders
Disk access is limited to folders you pick with the system dialog; paths outside them — `..`, absolute paths, symlink escapes — are rejected in Rust.
Reviewed writes
AI changes to files are shown as a diff and written only when you accept them, with Undo.
Terminal permissions
Commands run in a granted folder and only after you allow the exact command. Administrator actions are approved one by one, every time.
Processes
Everything Pogama starts is stopped — the whole process tree — when you stop it or quit the app.

Permissions

One checkpoint for everything sensitive.
Exact detail
Every request shows the exact command, path or URL. Allow once, for this session or project, or deny.
Deny wins
A deny anywhere overrides an allow. Sensitive defaults ask; access to environment variables is denied by default.
Per project
Set stricter or looser rules per project, on top of the global ones.

Audit system

A history you can verify.
What's recorded
Changes to settings, providers, keys (id only), permissions, files, commands, tools, MCP, chats and backups — who did it (you, the AI or the system) and the outcome.
Tamper-evident
Each entry includes the SHA-256 of the previous one; editing or deleting old entries is detected.
No content
The log records ids and names, never secret values or message content.

What we don't claim

Honesty is part of security.

Pogama is not certified against any compliance framework. Its development follows recognized references — OWASP ASVS, ISO/IEC 27002 controls, WCAG 2.2 — but following a standard isn't a certification, and we don't present it as one. To report a vulnerability, write to soporte@pogama.xyz.