Security
Design
- An observation or a model suggestion never becomes authority. Every state change needs a valid action schema, deterministic policy authorisation, any required approval, and post-action verification.
- Review the authorized windows before computer work. Use the stop controls or the emergency-stop shortcut shown in Settings if something goes wrong. Stopping cannot undo completed actions.
- Sign-in tokens are stored as hashes. Carve-managed provider keys are held by Carve Cloud; directly configured provider credentials are managed on your device. Relay content is not persisted.
- Spend breakers pause inference automatically if daily limits are reached, to help limit cost exposure; they do not guarantee every possible charge is prevented.
- The app’s local web boundary uses a rotating process capability, HttpOnly cookies, strict origin checks, and CSRF proof.
Reporting a vulnerability
Email support@getcarve.app with “Security” in the subject. We acknowledge reports within two business days and will not take action against good-faith research that avoids privacy violations, data destruction, and service disruption. Please do not test against other people’s accounts.