Skip to main content
Cryptographic Integrity & Zero Source Exfiltration

Local code, signed evidence, gated cloud access

Ozzy Dev is architected from the ground up for strict enterprise security. Your source code and semantic indexes never leave your Mac. Every consequential agent action produces a verifiable Ed25519 cryptographic receipt.

01 · Data Privacy

Mac-Local Trust Boundary

All repository indexing, AST parsing, symbol graphs, and search embeddings remain on your physical workstation on 127.0.0.1 loopback.

  • Zero source code cloud telemetry
  • Loopback origin security guards
127.0.0.1 Loopback · Local SQLite
02 · Audit Proof

Ed25519 Signed Receipts

Every code edit, search query, test ladder, and wave dispatch emits a tamper-evident Ed25519 receipt linked to a KnowYourModel agent card.

  • Offline-verifiable bundle — no network call needed
  • JCS canonical payload hashing
Ed25519 Signatures · KnowYourModel
03 · Access Control

Sentinel Cloud Auth Gate

Cloud console deployments enforce Sentinel OAuth authorization, role-based access control (RBAC), and session cookie cryptographic validation.

  • Default-denied admin endpoints
  • Cloudflare D1 encrypted vaults
Sentinel OAuth · Admin RBAC

Understand a Receipt Bundle Before Verification

This browser-side preview checks expected fields only. It does not claim cryptographic verification; the canonical receipt browser shows stored receipt metadata and related evidence.

Receipt Bundle Inspector

Structure only · signature unverified

Inspect whether a pasted bundle has the fields expected of an Ozzy Dev receipt. This preview does not verify its signature, issuer, or payload. Use the canonical receipt browser to inspect the recorded receipt metadata and any verification evidence available there.

Open the canonical receipt browser

Traditional Cloud AI vs. Ozzy Dev Enterprise Model

Security DimensionCloud Coding AssistantsOzzy Dev + Jade Planner
Source Code StorageUploaded to third-party vector cloud databases100% on-device local Mac filesystem (127.0.0.1)
Audit ProvenanceUnstructured chat logs and ephemeral tokensCryptographically signed Ed25519 Trust Receipts
Agent IdentityAnonymous API key with global accessKnowYourModel (KYM) cards with explicit permissions
Execution SafetySilent overwrite with unverified code diffsIsolated git worktrees + 4-rung test verify ladder

Security and trust by design

Explore our open-source security models or sign in with Sentinel.

Sign in with Sentinel