Security & privacy
Secure by construction.
Not by promise.
Pogama's safety comes from how it's built: what the interface can't do, it can't be tricked into doing. Here is exactly how — and where data does leave your computer.
Local-first
Your workspace lives on your computer.
- Stored locally
- Projects, chats, history, settings, captures and recordings.
- Leaves your computer
- What you send to the model provider you chose — messages, and files after you confirm sending them to a cloud model.
- Optional account
- Team tasks, licenses and Client Hub sync. Client credentials are encrypted on your device before they sync.
- Usage facts
- Feature counts and errors, never content, prompts, files, paths or keys. Turn them off in Settings → Privacy.
Credential storage
Keys live where your operating system keeps secrets.
- OS credential store
- Windows Credential Manager (Keychain on macOS, Secret Service on Linux).
- Write-only from the UI
- The interface can save a key but there is no command to read it back.
- Host-bound
- A key is attached by the native backend only to requests for the host it was saved for; changing the endpoint invalidates it.
- Never in logs
- Keys, bearer tokens and secret-looking values are redacted from every log.
AI provider boundaries
The model sees what you send it — nothing more.
- Through a native proxy
- Provider traffic goes through Pogama's Rust backend, which adds the key; the webview never holds it.
- Local or cloud, visible
- The message box says whether a model is local or in the cloud, and asks before files go to the cloud.
- Untrusted output
- Model output is treated as untrusted: rendered without raw HTML, never executed without your permission.
File & terminal access
Only the folders you open, only with your say.
- Granted folders
- Disk access is limited to folders you pick with the system dialog; paths outside them — `..`, absolute paths, symlink escapes — are rejected in Rust.
- Reviewed writes
- AI changes to files are shown as a diff and written only when you accept them, with Undo.
- Terminal permissions
- Commands run in a granted folder and only after you allow the exact command. Administrator actions are approved one by one, every time.
- Processes
- Everything Pogama starts is stopped — the whole process tree — when you stop it or quit the app.
Permissions
One checkpoint for everything sensitive.
- Exact detail
- Every request shows the exact command, path or URL. Allow once, for this session or project, or deny.
- Deny wins
- A deny anywhere overrides an allow. Sensitive defaults ask; access to environment variables is denied by default.
- Per project
- Set stricter or looser rules per project, on top of the global ones.
Audit system
A history you can verify.
- What's recorded
- Changes to settings, providers, keys (id only), permissions, files, commands, tools, MCP, chats and backups — who did it (you, the AI or the system) and the outcome.
- Tamper-evident
- Each entry includes the SHA-256 of the previous one; editing or deleting old entries is detected.
- No content
- The log records ids and names, never secret values or message content.
What we don't claim
Honesty is part of security.
Pogama is not certified against any compliance framework. Its development follows recognized references — OWASP ASVS, ISO/IEC 27002 controls, WCAG 2.2 — but following a standard isn't a certification, and we don't present it as one. To report a vulnerability, write to soporte@pogama.xyz.