Legal
Security
Last updated: 31 August 2026
Local-first architecture
Evidloom's core desktop runtime executes on your computer.
Chat transcripts, projects, learned skills, and most locally
configured tool credentials live in
~/.yupiter-studio/ on macOS and Linux or
%USERPROFILE%\.yupiter-studio\ on Windows.
We do not automatically mirror those directories to our servers.
Content you ask a hosted model to process can pass through the
model-provider routing described below.
macOS and Windows updater artifacts carry a Tauri updater signature that the bundled public key verifies before install. macOS builds are also Developer ID signed and notarized. The Windows installer is not Authenticode-signed and may show SmartScreen. Linux package updates are manual during the public preview.
Transport & auth
Connections between the desktop app and our hosted services use
HTTPS with TLS negotiated by the client platform and Cloudflare.
The LLM proxy at
proxy.evidloom.com requires a tenant bearer
token (a 40-character random string minted at signup) on
every request. Desktop credentials use macOS Keychain, Windows
Credential Manager, or a Linux libsecret-compatible keyring.
Linux fails closed when no system keyring is available; it does
not fall back to a plaintext credential file.
Desktop and paired-channel requests are bound to host-created device and request grants. Pairing uses an out-of-band one-time challenge, and high-risk effects retain exact-action review.
Hosted infrastructure
Public Studio edge services run on Cloudflare Workers. Usage records live in Cloudflare D1 and tenant tokens in Cloudflare KV. These are pooled services: records are logically partitioned by tenant identifiers and authorization checks. That is not a claim of dedicated physical infrastructure per tenant.
Stripe handles billing. We never see your full card number, CVV, or any payment details beyond what Stripe surfaces to us as a Payment Method ID + last-4 digits. Stripe-hosted card entry reduces our PCI scope; it does not remove our security responsibilities.
Model-provider routing
When the agent calls a language model, the request passes through our proxy on its way to the model provider (OpenAI, Anthropic, etc.). The proxy logs token counts and cost; it does not log prompt or response content. Our provider keys are stored as Cloudflare Worker secrets (KMS-encrypted, never exposed to the Worker code as plain strings beyond the request handler).
If you choose bring-your-own-keys mode, your provider API key is transmitted over HTTPS and stored in hosted encrypted infrastructure so Evidloom's proxy can use it. BYOK requests still pass through the proxy; inference charges go to your provider account.
Agent permissions & auditing
The agent works on your machine as you: commands and the tools it writes run with your own environment and access, exactly as if you had typed them, so what it can reach is what you can reach. Every action goes through an explicit, typed tool surface and is recorded in the audit log. The agent requires your explicit confirmation before irreversible deletion, moving money, exporting stored credentials, rewriting Git history, elevating privileges, or publishing publicly, and you can stop everything at any time with STOP ALL or switch off the code it writes with one toggle.
On macOS, the app requests Accessibility, Screen Recording, and Microphone permissions individually via the standard macOS prompts — we never silently grant ourselves access.
Reporting a vulnerability
We take security reports seriously. Please email [email protected] with the subject line "Security vulnerability" and as much detail as you can share. We acknowledge reports within 24 hours and aim to fix verified issues within 7 days for critical severity, 30 days otherwise. We won't pursue legal action against researchers acting in good faith.
What's next on our roadmap
SOC 2 Type I in 2026 Q4. Customer-specific encryption keys for tenant-stored data in 2027. We'll update this page when those land.