Security
Your workspace stays on your device.
Your data
What stays local.
What leaves, and when.
Every kind of data Athas touches, with its default handling and the moment it can leave your machine.
Workspace and source code
Kept on your device and excluded from Athas telemetry. When you choose a remote workflow, such as sending context to an AI provider.
AI prompts and selected context
Processed only when you invoke an AI feature. Sent to the provider or endpoint you selected. Local endpoints keep the request local.
API keys and connection secrets
Stored locally with operating-system secure storage when available. Used to authenticate directly with the service you configured.
Usage telemetry
Off by default. Only after you opt in; update checks still send limited operational metadata.
Account and billing data
Limited to operating account, support, and paid-service features. Shared with the service providers needed to deliver those features.
Releases and updates
Verified builds.
Signed updates.
Every release is checksummed and signed so you can confirm what you install is what we shipped.
Checksums for release artifacts
The release pipeline produces a SHA-256 checksum manifest so downloaded artifacts can be verified.
Signed desktop updates
Athas validates updater signatures before applying an update delivered through its release channels.
Platform signing checks
Release preflight validates platform signing and notarization credentials when those channels are configured.
Hardened web delivery
The website uses HTTPS with HSTS, framing protection, content-type protection, and a restrictive permissions policy.
Report a vulnerability
Found something? Tell us privately.
Use GitHub private vulnerability reporting for security-sensitive details. Include the affected version and platform, reproduction steps, expected impact, and any useful logs or proof of concept. If GitHub is unavailable, email [email protected].
Further reading
Go deeper.
Policies, documentation, and artifacts behind everything on this page.