Security overview

Keep authority outside the model.

Garden Desk treats generated instructions as untrusted. The application—not the model—owns access, execution, limits, evidence, and teardown.

Local and offline-first

Core product work is designed to run on the owner’s computer without a mandatory cloud service or silent cloud fallback. The desktop has no application telemetry.

Restricted execution

Agent-authored commands run inside a bounded virtual machine with no network interface. It receives a live read-only view of the selected source folder and a small, separate writable workspace. The model does not receive a host shell.

Typed boundaries and visible evidence

The application validates and authorizes actions through typed boundaries. Session activity, bounded execution output, generated-file records, and local audit evidence remain available for review.

Current certification status

The macOS M3 stage has physical Apple-silicon evidence. Windows product integration and physical certification remain in progress. macOS results are not treated as proof for Windows, and public signed installers are not yet available.

Report a vulnerability

Do not publish vulnerability details in a public issue, discussion, or chat. Follow the repository security policy for private reporting instructions and safe fallback contact.