Local code, signed evidence, gated cloud access
Ozzy Dev is architected from the ground up for strict enterprise security. Your source code and semantic indexes never leave your Mac. Every consequential agent action produces a verifiable Ed25519 cryptographic receipt.
Mac-Local Trust Boundary
All repository indexing, AST parsing, symbol graphs, and search embeddings remain on your
physical workstation on 127.0.0.1 loopback.
- Zero source code cloud telemetry
- Loopback origin security guards
Ed25519 Signed Receipts
Every code edit, search query, test ladder, and wave dispatch emits a tamper-evident Ed25519 receipt linked to a KnowYourModel agent card.
- Offline-verifiable bundle — no network call needed
- JCS canonical payload hashing
Sentinel Cloud Auth Gate
Cloud console deployments enforce Sentinel OAuth authorization, role-based access control (RBAC), and session cookie cryptographic validation.
- Default-denied admin endpoints
- Cloudflare D1 encrypted vaults
Operator Workstation Security Posture
Automated, non-destructive configuration compliance & developer threat surface inspection on macOS & PCs.
3-Tier Remediation Ladder — All Workstation Tiers Clean
Issues are classified into three calibrated operational tiers to avoid developer environment disruption:
Zero sudo required. Completely non-destructive and reversible.
System firewall & daemon services requiring root elevation.
Interactive passphrase addition & System Settings navigation.
Prevents rootkits and unauthorized binary injection into Apple system locations.
Ensures the root filesystem snapshot cryptographically matches Apple’s signed Merkle tree.
Blocks execution of unsigned or non-notarized malicious executables.
Prevents background user processes from intercepting keystrokes typed in Terminal.
Executes scheduled background remediation sweeps against active macOS malware families.
Protects source code and secrets at rest against physical device theft.
Blocks unsolicited incoming network connections on Wi-Fi/LAN without impacting localhost dev.
Silently discards ICMP ping probes so developer workstation is invisible on untrusted networks.
Prevents lateral network movement into workstation over remote SSH connections.
Prevents local drive-by DNS rebinding attacks against open Chrome DevTools or Node debug ports.
Unencrypted private keys can be copied by any user-level process to authenticate as the operator.
Plaintext git credential helpers write API tokens directly to ~/.git-credentials.
Ensures AWS credential files are not world-readable by local developer processes.
Guarantees .env files containing production API keys are not committed to git.
Tokens entered in terminal commands persist in plaintext shell history.
Detects unauthorized shell-wrapped or Trojan persistence items in ~/Library/LaunchAgents.
Validates that background daemons are notified to the user and not running in stealth.
Restricts the privilege escalation window after a sudo command is executed.
Prevents low-privilege processes from planting Trojan binaries overriding standard utilities.
Ensures terminal app does not leak unconstrained Full Disk Access to AI agent child shells.
Understand a Receipt Bundle Before Verification
This browser-side preview checks expected fields only. It does not claim cryptographic verification; the canonical receipt browser shows stored receipt metadata and related evidence.
Receipt Bundle Inspector
Inspect whether a pasted bundle has the fields expected of an Ozzy Dev receipt. This preview does not verify its signature, issuer, or payload. Use the canonical receipt browser to inspect the recorded receipt metadata and any verification evidence available there.
Traditional Cloud AI vs. Ozzy Dev Enterprise Model
| Security Dimension | Cloud Coding Assistants | Ozzy Dev + Jade Planner |
|---|---|---|
| Source Code Storage | Uploaded to third-party vector cloud databases | 100% on-device local Mac filesystem (127.0.0.1) |
| Audit Provenance | Unstructured chat logs and ephemeral tokens | Cryptographically signed Ed25519 Trust Receipts |
| Agent Identity | Anonymous API key with global access | KnowYourModel (KYM) cards with explicit permissions |
| Execution Safety | Silent overwrite with unverified code diffs | Isolated git worktrees + 4-rung test verify ladder |
Security and trust by design
Explore our open-source security models or sign in with Sentinel.
Sign in with Sentinel