Your machine stays yours

Security

Bisa runs on your machine, under your account, with keys you hold. Its protections are on from the first run and stay out of the way of the work. They are best effort, not a sandbox — and this page says exactly where they stop.

Local-first

  • A workspace is a directory, ~/.bisa. There is no account, no server to sign up for and nothing deployed; its index is a cache that can be deleted at any moment without loss.
  • Bisa contains no model client. Your harnesses talk to their own providers, signed in as you, as they would in a terminal.
  • Bisa never writes into a folder it did not create, installs nothing and signs in to nothing for you: where something is missing, it shows the official line to copy.
  • The diagnostic log stays on your machine.

What leaves your machine, and what turns it off

No Bisa server, no analytics. Bisa contacts only services you already use or switch on:

ContactedWhenOff
Your harness's model providerwhenever the harness works — by the harness, not by Bisa; secrets the redactor recognises are placeholders by thenthe harness's own settings
Your harness's usage sourcewhen the footer or Settings asks what an account has leftharness.usage.reads
The public-IP echo and two public resolverswhen the desktop reads this machine's network for its footer wordnetwork.public_ip_url empty stops the echo
Nostr relaysonly once you turn sync onsync.enabled — off by default
Your code hostwhen you push, open or read a pull request — each push through the publish gatethe project's publish policy
A connector's platformwhen a workflow you started calls it, with an account you addedsecurity.net.deny_hosts refuses a host whatever a connector declares
Jev, or a calibrated model's endpointonly when you choose it to judgedecisions.provider
An addon's declared hoststhrough the platform's broker, only with the grant you gavethe addon's grants
Pages in the embedded browserwhat you or an agent opens—

Inbound, a public hook answers only once events.public_hooks is on — and the node listens on this machine alone unless started to allow more.

Keys and identity

  • A Nostr keypair minted on first run is your identity — your npub. It lives in an owner-only file, or in the OS keyring if you choose it.
  • Every agent has its own keypair, attested by yours, so its work is signed as itself; your key signs only what you did.
  • The control plane takes a bearer token of 32 random bytes in an owner-only file. It is never exported into a terminal or handed to a harness.

Encryption, end to end between nodes

Collaboration is optional. When it is on, every fact that leaves your node is sealed for one recipient with NIP-44 and gift-wrapped with NIP-59, for each person who may read it — there is no shared key.

  • A relay sees a sealed envelope: ciphertext, a recipient key, when it arrived and its size. Never what the fact is, who wrote it or what it says.
  • Unwrapping checks that the author inside is the sender of the seal, and the inner signature is verified again before anything is admitted — by role.
  • Direct messages are encrypted pairwise to the people in them. An agent's private memory is encrypted to you, under a blinded tag.
  • In a hosted workspace the host's node is an end: it opens what it receives and seals it again for each member who may read it.
  • Removing someone stops what they receive from then on; what already reached them cannot be un-sent.
  • Notes, workstreams, keys, MCP configurations, connector accounts and hook secrets never travel at all.

The three guards

The Redactor

A key, a token or a value the rules recognise never reaches an agent, a harness or a remote, and never sits raw in a journal, a message or a commit an agent wrote. It travels as a placeholder the agent can still use — «secret:github_token:7f3a2c» — restored only where a command is about to run on this machine. It recognises private keys and the token shapes of the common clouds, code hosts and model providers, credentials in URLs and secret-looking assignments, and the values of environment variables whose names say they are secrets.

The Tool & Commands Guard

Every command, path and tool a guarded harness is about to run is judged first by ordered rules — allow, deny, ask, classify — the built-in refusals first, then the workspace's, then this machine's. Built in: recursive deletes, privilege escalation, a download piped into a shell, forced pushes, hard resets, history rewrites, and credential paths such as ~/.ssh, ~/.aws and .env files. A call above its step's ceiling is put to a person; an answer is remembered for the goal.

The Classifier

A model reads the redacted call and answers one line: SAFE, or HARMFUL and why. Anything else is no verdict, which goes to you. It never allows what the rules did not. It also reads what comes from outside — a public hook's body, a connector's item, a page an agent reads, a message from another node — and only a sure safe passes on its own.

Which harness is guarded

Only a harness that asks before a tool runs, and obeys a refusal, can be guarded. The honest table:

HarnessThe guard's reach
Claude Code, driven by Bisa or in a terminaljudged before it runs; placeholders restored
Any ACP agent — GitHub Copilot CLI and Grok Build among them — driven by Bisajudged before it runs
GitHub Copilot CLI in a terminaljudged before it runs
Grok Build in a terminalnot seen — a plain terminal
Codex CLI, pi, Oh My Pi, OpenCode, a custom harness, an A2A agentobserved: under the harness's own sandbox and prompt, reported and redacted, not vetoed

Gates

  • Approval — a step that waits for a person's signed yes.
  • Escalation — a question or a call above a step's ceiling, put to a person.
  • Publish — a push or a pull request, where work leaves your machine: per project, manual, gated or auto.
  • You choose who may decide: only you, you and the admins, every member, or a list. An agent proposes; a person adopts. A judgement never signs a gate.

Nothing unrecoverable

  • Every git operation that moves your tree writes a recovery ref first; Restore, under Safety, is the undo. Agents have no path to those operations.
  • Saves are compare-and-swap: a file changed under you opens a three-way merge, never a lost edit.
  • Nothing is deleted while something points at it, and the refusal names what is holding it. A project's folder goes to the Trash only when you ask, and never one you adopted.

Where it stops

  • Best effort, not a sandbox. An observed harness runs under its own sandbox; a shell in a terminal can go anywhere your account can; Full Disk Access, which the app recommends for productivity, widens what anything running can reach.
  • Workstreams are separate checkouts, not containers.
  • The redactor does not reach a file an agent reads with its own tools, what you type into your own terminal, a harness's transcript on disk, or the bytes of an image.
  • A harness's own web tools, and MCP servers you install, are outside the content screen.
  • The A2A endpoint takes no token: on this machine, any local process can submit to it.

The security architecture, in full

Report a vulnerability

Please report privately, through GitHub's vulnerability reporting on the repository — never in a public issue. The security policy says what to include and what to expect. A release is a signed, notarized disk image with its SHA-256: verify a download.