Security

Security is built from verifiable boundaries

We describe implemented mechanisms and separate source completion from external checks that still need to finish before public rollout.

01

Secrets and activation

Desktop stores license material, service keys, and proxy passwords in a versioned envelope backed by operating-system protected storage. The UI receives configuration state, not secret values.

  • Signed activation with server-side entitlement checks
  • Fail-closed startup when secure storage is unavailable
  • Factory reset removes local secrets and customer state
02

Delivery and updates

Encrypted Chromium bundles are checked with SHA-256. Release manifests bind version, size, digest, key, and validity window; the Windows signature policy is bound into activation.

03

VLM privacy

Remote screenshots are used only after explicit consent. Input fields, private regions, and iframes are masked; each request is limited to one JPEG, a short-lived token, and a fixed response schema.

04

Clear limits

Automation cannot eliminate blocking and does not replace platform rules. Public rollout, commercial Windows signing, and remaining external acceptance campaigns are independent gates.

PROJECT GHOST

Request access

Request access