Privacy and security

Security overview for reviewers.

The questions a security review asks first, answered on one page. Print it or share the link.

Written for Murage 0.1.60. The detail behind each point is in the security model guide.

The facts.

How it runs

  • Murage is a desktop app for macOS, Windows and Ubuntu. Each person runs their own copy on their own computer.
  • Its built-in server listens only on that computer (127.0.0.1), never on the network.
  • Bots, conversations, memory, files and settings live in Murage’s data folder in the user’s home folder, made readable by that user only. There is no Murage server holding the work.
  • No Murage account is needed to download or use the app.

Where data goes

  • Only to what the user connects: the AI engine chosen for each bot, connected apps (through Flux Router’s connected apps or the user’s own connected-apps key), voice and web search services, Telegram, Slack or Discord if paired, and off-site backups to storage the user owns (an S3-compatible bucket or their own SFTP server).
  • A bot on a local model sends nothing about its turns to a cloud provider.
  • Flux Router is an optional, credit-billed service run by Ferrox Labs. It passes each request to the provider that serves it.
  • The app checks GitHub for updates. An optional name and email at first run is sent to us for product updates; skipping it sends nothing.
  • Usage analytics: today’s releases send none. Anonymous, opt-out analytics are planned.

Keys and credentials

  • API keys and tokens are encrypted with the operating system’s secure storage (the Keychain on a Mac, and the equivalent on Windows and Ubuntu).
  • Keys are write-only inside Murage: never shown back, logged or passed on a command line.
  • Engines such as Claude Code and Codex keep their own sign-in. Murage uses it; it doesn’t copy it.

Access levels and the stop line

  • Ask (the default for every new bot and every imported team): the bot asks before each action it tells Murage about. Answers are Allow once, Allow for this task, Always allow, Always allow this exact command here (that command, folder and engine only), or Deny. Every remembered grant is listed per bot and can be removed.
  • Auto: keeps going, but asks about anything destructive. The stop line applies.
  • Full access: keeps going without asking, but stops before messaging anyone new, posting publicly, paying, or deleting outside its folder, unless the user has allowed it for that task. Replies in an existing conversation go ahead.
  • Engine coverage: the stop line judges the permission requests that reach Murage. On Claude Code and Codex, it also covers tools from MCP servers the user adds. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: Hermes asks before shell commands and file edits, but not before MCP or connected-app tools.
  • No limits: turns the stop line off. It can be switched on only in the desktop app, after a warning. Reading keys and passwords still asks.
  • Webhook runs are judged as Auto, whatever the bot’s level. Each routine runs at its own level; one the user hasn’t set follows the bot’s level. Reading keys and passwords asks at every level.
  • Only the user’s own desktop app and paired devices can answer an approval card. A message whose sender Murage can’t confirm runs as an unattended turn.
  • The stop line is an automated check on the actions a bot tries to take. It is a backstop, not a sandbox: a bot on Auto or Full access runs with the user’s own permissions.
  • The stop line is code: server/stop-line.ts, with its table tests in server/stop-line.test.ts.

Untrusted content and skills

  • Emails, web pages, channel messages and webhook payloads reach bots labeled as untrusted. The default House Rules say outside text can inform a bot but never instruct it.
  • Skill Guard scans every skill offline on import, install, edit and at start-up. Imported skills land switched off.
  • Imported teams arrive on Ask with skills off, routines paused and no connected apps. Exports never include credentials, conversations, memory or permission grants.

What isn’t there yet

  • No SOC 2, HIPAA or outside security audit.
  • No central admin console or settings lock. Each person controls their own copy, so any user can choose No limits for their own bots.
  • No shared, always-on workspace. That comes with Murage Cloud, which isn’t open yet.
  • Rollout is package distribution: build a team once, export it, and each person imports it on their own computer and connects their own accounts.

License and verification

  • The app is open source under AGPL-3.0-or-later from version 0.1.59. A commercial license is available on request.
  • Mac builds are signed and notarized by Apple, and Windows builds are signed. Every installer lists its SHA-256 checksum on the download page.
  • The full source code is public on GitHub, so your team can read exactly what the app stores and sends.

Report a problem, or ask us.