Your machine stays yours
Security
Bisa runs on your machine, under your account, with keys you hold. Its protections are on from the first run and stay out of the way of the work. They are best effort, not a sandbox — and this page says exactly where they stop.
Local-first
- A workspace is a directory,
~/.bisa. There is no account, no server to sign up for and nothing deployed; its index is a cache that can be deleted at any moment without loss. - Bisa contains no model client. Your harnesses talk to their own providers, signed in as you, as they would in a terminal.
- Bisa never writes into a folder it did not create, installs nothing and signs in to nothing for you: where something is missing, it shows the official line to copy.
- The diagnostic log stays on your machine.
What leaves your machine, and what turns it off
No Bisa server, no analytics. Bisa contacts only services you already use or switch on:
| Contacted | When | Off |
|---|---|---|
| Your harness's model provider | whenever the harness works — by the harness, not by Bisa; secrets the redactor recognises are placeholders by then | the harness's own settings |
| Your harness's usage source | when the footer or Settings asks what an account has left | harness.usage.reads |
| The public-IP echo and two public resolvers | when the desktop reads this machine's network for its footer word | network.public_ip_url empty stops the echo |
| Nostr relays | only once you turn sync on | sync.enabled — off by default |
| Your code host | when you push, open or read a pull request — each push through the publish gate | the project's publish policy |
| A connector's platform | when a workflow you started calls it, with an account you added | security.net.deny_hosts refuses a host whatever a connector declares |
| Jev, or a calibrated model's endpoint | only when you choose it to judge | decisions.provider |
| An addon's declared hosts | through the platform's broker, only with the grant you gave | the addon's grants |
| Pages in the embedded browser | what you or an agent opens | — |
Inbound, a public hook answers only once events.public_hooks is on — and the node listens on this machine alone unless started to allow more.
Keys and identity
- A Nostr keypair minted on first run is your identity — your
npub. It lives in an owner-only file, or in the OS keyring if you choose it. - Every agent has its own keypair, attested by yours, so its work is signed as itself; your key signs only what you did.
- The control plane takes a bearer token of 32 random bytes in an owner-only file. It is never exported into a terminal or handed to a harness.
Encryption, end to end between nodes
Collaboration is optional. When it is on, every fact that leaves your node is sealed for one recipient with NIP-44 and gift-wrapped with NIP-59, for each person who may read it — there is no shared key.
- A relay sees a sealed envelope: ciphertext, a recipient key, when it arrived and its size. Never what the fact is, who wrote it or what it says.
- Unwrapping checks that the author inside is the sender of the seal, and the inner signature is verified again before anything is admitted — by role.
- Direct messages are encrypted pairwise to the people in them. An agent's private memory is encrypted to you, under a blinded tag.
- In a hosted workspace the host's node is an end: it opens what it receives and seals it again for each member who may read it.
- Removing someone stops what they receive from then on; what already reached them cannot be un-sent.
- Notes, workstreams, keys, MCP configurations, connector accounts and hook secrets never travel at all.
The three guards
The Redactor
A key, a token or a value the rules recognise never reaches an agent, a harness or a remote, and never sits raw in a journal, a message or a commit an agent wrote. It travels as a placeholder the agent can still use — «secret:github_token:7f3a2c» — restored only where a command is about to run on this machine. It recognises private keys and the token shapes of the common clouds, code hosts and model providers, credentials in URLs and secret-looking assignments, and the values of environment variables whose names say they are secrets.
The Tool & Commands Guard
Every command, path and tool a guarded harness is about to run is judged first by ordered rules — allow, deny, ask, classify — the built-in refusals first, then the workspace's, then this machine's. Built in: recursive deletes, privilege escalation, a download piped into a shell, forced pushes, hard resets, history rewrites, and credential paths such as ~/.ssh, ~/.aws and .env files. A call above its step's ceiling is put to a person; an answer is remembered for the goal.
The Classifier
A model reads the redacted call and answers one line: SAFE, or HARMFUL and why. Anything else is no verdict, which goes to you. It never allows what the rules did not. It also reads what comes from outside — a public hook's body, a connector's item, a page an agent reads, a message from another node — and only a sure safe passes on its own.
Which harness is guarded
Only a harness that asks before a tool runs, and obeys a refusal, can be guarded. The honest table:
| Harness | The guard's reach |
|---|---|
| Claude Code, driven by Bisa or in a terminal | judged before it runs; placeholders restored |
| Any ACP agent — GitHub Copilot CLI and Grok Build among them — driven by Bisa | judged before it runs |
| GitHub Copilot CLI in a terminal | judged before it runs |
| Grok Build in a terminal | not seen — a plain terminal |
| Codex CLI, pi, Oh My Pi, OpenCode, a custom harness, an A2A agent | observed: under the harness's own sandbox and prompt, reported and redacted, not vetoed |
Gates
- Approval — a step that waits for a person's signed yes.
- Escalation — a question or a call above a step's ceiling, put to a person.
- Publish — a push or a pull request, where work leaves your machine: per project, manual, gated or auto.
- You choose who may decide: only you, you and the admins, every member, or a list. An agent proposes; a person adopts. A judgement never signs a gate.
Nothing unrecoverable
- Every git operation that moves your tree writes a recovery ref first; Restore, under Safety, is the undo. Agents have no path to those operations.
- Saves are compare-and-swap: a file changed under you opens a three-way merge, never a lost edit.
- Nothing is deleted while something points at it, and the refusal names what is holding it. A project's folder goes to the Trash only when you ask, and never one you adopted.
Where it stops
- Best effort, not a sandbox. An observed harness runs under its own sandbox; a shell in a terminal can go anywhere your account can; Full Disk Access, which the app recommends for productivity, widens what anything running can reach.
- Workstreams are separate checkouts, not containers.
- The redactor does not reach a file an agent reads with its own tools, what you type into your own terminal, a harness's transcript on disk, or the bytes of an image.
- A harness's own web tools, and MCP servers you install, are outside the content screen.
- The A2A endpoint takes no token: on this machine, any local process can submit to it.
Report a vulnerability
Please report privately, through GitHub's vulnerability reporting on the repository — never in a public issue. The security policy says what to include and what to expect. A release is a signed, notarized disk image with its SHA-256: verify a download.