Security overview
Keep authority outside the model.
Garden Desk treats generated instructions as untrusted. The application—not the model—owns access, execution, limits, evidence, and teardown.
Local and offline-first
Core product work is designed to run on the owner’s computer without a mandatory cloud service or silent cloud fallback. The desktop has no application telemetry.
Restricted execution
Agent-authored commands run inside a bounded virtual machine with no network interface. It receives a live read-only view of the selected source folder and a small, separate writable workspace. The model does not receive a host shell.
Typed boundaries and visible evidence
The application validates and authorizes actions through typed boundaries. Session activity, bounded execution output, generated-file records, and local audit evidence remain available for review.
Current certification status
The macOS M3 stage has physical Apple-silicon evidence. Windows product integration and physical certification remain in progress. macOS results are not treated as proof for Windows, and public signed installers are not yet available.
Report a vulnerability
Do not publish vulnerability details in a public issue, discussion, or chat. Follow the repository security policy for private reporting instructions and safe fallback contact.