Security at Deskfolk
Clear boundaries for private work.
Deskfolk is local first. Hosted and sync features are explicit choices, and remote access is scoped to an authenticated account and its paired devices.
Local-first data
Local bot profiles, transcripts, skills, provider credentials, and computer profiles stay on the Mac by default. Deskfolk sends data to its hosted services only when you enable a feature that needs them, such as sync or a hosted bot.
Account and tenant boundaries
Remote workspaces use authenticated, tenant-scoped routing. Devices, synced events, connectors, hosted-bot limits, and billing state are resolved within that workspace rather than from identifiers supplied by an unauthenticated client.
Hosted sleep state
Selected hosted bots wake for work and sleep when idle. The restorable configuration saved for a sleeping hosted bot is encrypted; the running computer receives short-lived access scoped to its work.
Report a security issue
Email security@deskfolk.app with a concise description, affected surface, reproduction steps, and the impact you observed. Please avoid accessing other people's data, disrupting the service, or including secrets and personal data that are not needed to explain the issue.
Responsible disclosure
Please give us a reasonable opportunity to investigate and address a report before publishing details. We will use the contact information in your report only to coordinate the investigation and remediation.