Skip to main content
Cryptographic Integrity & Zero Source Exfiltration

Local code, signed evidence, gated cloud access

Ozzy Dev is architected from the ground up for strict enterprise security. Your source code and semantic indexes never leave your Mac. Every consequential agent action produces a verifiable Ed25519 cryptographic receipt.

01 · Data Privacy

Mac-Local Trust Boundary

All repository indexing, AST parsing, symbol graphs, and search embeddings remain on your physical workstation on 127.0.0.1 loopback.

  • Zero source code cloud telemetry
  • Loopback origin security guards
127.0.0.1 Loopback · Local SQLite
02 · Audit Proof

Ed25519 Signed Receipts

Every code edit, search query, test ladder, and wave dispatch emits a tamper-evident Ed25519 receipt linked to a KnowYourModel agent card.

  • Offline-verifiable bundle — no network call needed
  • JCS canonical payload hashing
Ed25519 Signatures · KnowYourModel
03 · Access Control

Sentinel Cloud Auth Gate

Cloud console deployments enforce Sentinel OAuth authorization, role-based access control (RBAC), and session cookie cryptographic validation.

  • Default-denied admin endpoints
  • Cloudflare D1 encrypted vaults
Sentinel OAuth · Admin RBAC
Endpoint Security Engine · NIST SP 800-219 & CIS Level 1/2

Operator Workstation Security Posture

Automated, non-destructive configuration compliance & developer threat surface inspection on macOS & PCs.

Compliance Score
100% (20/20 rules)
Workstation Target
Apple Silicon (macOS)
SIP & FileVault Hardware Anchored
Active Scan Profile
Latest Trust Receipt
rc-06GBX6RFN1XYP91GESME0D1
Open Receipt Door

3-Tier Remediation Ladder — All Workstation Tiers Clean

100% Compliant

Issues are classified into three calibrated operational tiers to avoid developer environment disruption:

Tier 1 · Auto-Safe 0 ready

Zero sudo required. Completely non-destructive and reversible.

Tier 2 · Privileged (Sudo) 0 items

System firewall & daemon services requiring root elevation.

Tier 3 · Manual / Hardware 0 items

Interactive passphrase addition & System Settings navigation.

System Integrity Protection (SIP) Enforced os_sip_enable
critical compliant

Prevents rootkits and unauthorized binary injection into Apple system locations.

Evidence: System Integrity Protection status: enabled.
NIST SI-2 · CIS 5.1.1 · STIG APPL-000120
Authenticated Root Sealed System Volume (SSV) Enforced os_authenticated_root_enable
critical compliant

Ensures the root filesystem snapshot cryptographically matches Apple’s signed Merkle tree.

Evidence: Authenticated Root status: enabled
NIST SI-7 · CIS 5.1.2
Gatekeeper & Notarization Assessment Enforced os_gatekeeper_enable
high compliant

Blocks execution of unsigned or non-notarized malicious executables.

Evidence: assessments enabled
NIST SI-3 · CIS 5.2.1
Terminal Secure Keyboard Entry Enforced os_terminal_secure_keyboard_enable
low compliant

Prevents background user processes from intercepting keystrokes typed in Terminal.

Evidence: SecureKeyboardEntry = 1
NIST AC-17 · CIS 5.14
Apple XProtect Malware Defense Service Active os_xprotect_service_active
high compliant

Executes scheduled background remediation sweeps against active macOS malware families.

Evidence: com.apple.XProtect service registered in launchctl
NIST SI-3 · CIS 5.11
FileVault Full Disk Encryption Enforced system_settings_filevault_enforce
critical compliant

Protects source code and secrets at rest against physical device theft.

Evidence: FileVault is On.
NIST SC-13 · CIS 2.5.1 · STIG APPL-000020
Host Application Firewall Enforced system_settings_firewall_enable
high compliant

Blocks unsolicited incoming network connections on Wi-Fi/LAN without impacting localhost dev.

Evidence: Firewall is enabled. (State = 1)
NIST SC-7 · CIS 2.3.1 · STIG APPL-000080
Firewall Stealth Mode Enforced system_settings_firewall_stealth_mode_enable
medium compliant

Silently discards ICMP ping probes so developer workstation is invisible on untrusted networks.

Evidence: Stealth mode status: enabled
NIST SC-7(4) · CIS 2.3.2
Remote Login (SSH Daemon) Disabled or Audited system_settings_ssh_disable
medium compliant

Prevents lateral network movement into workstation over remote SSH connections.

Evidence: com.openssh.sshd is inactive in launchctl
NIST AC-17 · CIS 2.4.1
No Exposed Unauthenticated Debug Sockets dev_open_debug_sockets
critical compliant

Prevents local drive-by DNS rebinding attacks against open Chrome DevTools or Node debug ports.

Evidence: No wildcard debug sockets (9222/9229/5858) listening
NIST SC-7 · AC-3
SSH Private Keys Encrypted with Passphrase dev_unencrypted_ssh_keys
high compliant

Unencrypted private keys can be copied by any user-level process to authenticate as the operator.

Evidence: All examined SSH private keys are passphrase-encrypted (aes256-ctr)
NIST IA-5 · SC-28
Git Credential Storage Uses Encrypted Keychain dev_git_credential_helper_secure
high compliant

Plaintext git credential helpers write API tokens directly to ~/.git-credentials.

Evidence: Git credential helper is secure (osxkeychain) with ~/.git-credentials backed up
NIST IA-5 · SC-28
AWS Cloud Credentials Storage Security dev_aws_credentials_plaintext
high compliant

Ensures AWS credential files are not world-readable by local developer processes.

Evidence: ~/.aws/credentials file not present or strict 0600 mode
NIST IA-5 · AC-3
Workspace Free of Live Plaintext Secrets dev_unprotected_env_secrets
high compliant

Guarantees .env files containing production API keys are not committed to git.

Evidence: No unprotected high-entropy keys in workspace root
NIST SC-28 · AC-3
Shell History Free of Plaintext API Tokens dev_shell_history_secrets
medium compliant

Tokens entered in terminal commands persist in plaintext shell history.

Evidence: No plaintext secret export patterns in recent shell history (sanitized)
NIST AU-3 · IA-5
User LaunchAgents Verified for Integrity os_launchd_user_agents
high compliant

Detects unauthorized shell-wrapped or Trojan persistence items in ~/Library/LaunchAgents.

Evidence: User LaunchAgents evaluated with no suspicious shell wrappers
NIST CM-7 · CIS 2.8
Background Task Management (BTM) Integrity os_btm_disposition_audit
medium compliant

Validates that background daemons are notified to the user and not running in stealth.

Evidence: BTM database verified clean of silent unnotified items
NIST CM-7 · SI-4
Sudo Timestamp Timeout Bounded (<=5 min) os_sudo_timeout_configure
high compliant

Restricts the privilege escalation window after a sudo command is executed.

Evidence: sudo timestamp timeout bounded
NIST AC-2 · CIS 5.3
PATH Free of World-Writable Directories os_path_security
high compliant

Prevents low-privilege processes from planting Trojan binaries overriding standard utilities.

Evidence: All PATH directories verified non-world-writable
NIST SI-16 · CIS 5.10
Agent Execution Environment Privilege & TCC Isolation os_tcc_agent_fda_privilege_audit
medium compliant

Ensures terminal app does not leak unconstrained Full Disk Access to AI agent child shells.

Evidence: Active shell does not hold unrestricted Full Disk Access
NIST AC-6 · SC-3

Understand a Receipt Bundle Before Verification

This browser-side preview checks expected fields only. It does not claim cryptographic verification; the canonical receipt browser shows stored receipt metadata and related evidence.

Receipt Bundle Inspector

Structure only · signature unverified

Inspect whether a pasted bundle has the fields expected of an Ozzy Dev receipt. This preview does not verify its signature, issuer, or payload. Use the canonical receipt browser to inspect the recorded receipt metadata and any verification evidence available there.

Open the canonical receipt browser

Traditional Cloud AI vs. Ozzy Dev Enterprise Model

Security DimensionCloud Coding AssistantsOzzy Dev + Jade Planner
Source Code StorageUploaded to third-party vector cloud databases100% on-device local Mac filesystem (127.0.0.1)
Audit ProvenanceUnstructured chat logs and ephemeral tokensCryptographically signed Ed25519 Trust Receipts
Agent IdentityAnonymous API key with global accessKnowYourModel (KYM) cards with explicit permissions
Execution SafetySilent overwrite with unverified code diffsIsolated git worktrees + 4-rung test verify ladder

Security and trust by design

Explore our open-source security models or sign in with Sentinel.

Sign in with Sentinel