Trust starts with explicit boundaries.

Kaplira governs coding-agent work without pretending every part of the stack is under its control. Here is what stays local, what can leave, and where the boundary ends.

Know where information lives.

On your device

The working system stays local.

Your active repository, technical index, project graph, and Kaplira run records remain on your computer.

Selected provider

Only materialized task context can leave it.

When a run uses an external provider, Kaplira materializes task-specific context for that selected route. The provider's own data terms still apply.

Receipt export

The standard record is deliberately narrow.

Standard exports omit diff bodies, source contents, prompts, command output, credentials, and secrets. A detailed export may include diffs when you explicitly select it.

The contract is structured, not implied.

A governed run can carry explicit permissions and architecture scope. The structured contract is the authoritative boundary used by pre-edit and review gates.

  • Readable and writable paths
  • Commands the agent may run
  • Network access mode
  • Architecture blocks that are in or out of scope

Governance is not a blanket security claim.

Each limit a reviewer should know before relying on Kaplira, paired with what does hold.

  • Model providers

    Not claimed

    Kaplira does not replace a model provider's privacy or security terms.

    What does hold

    Only the task context materialized for a run you route to that provider can leave your device.

  • Receipt integrity

    Not claimed

    Current receipts do not claim a cryptographic signer or independent authenticity proof.

    What does hold

    A receipt checksum checks that the recorded content is consistent.

  • Writes outside Kaplira

    Not claimed

    Writes made entirely outside a governed Kaplira path cannot always be prevented in advance.

    What does hold

    Later diff capture and review can surface them.

  • Compliance

    Not claimed

    Kaplira does not currently claim SOC 2, ISO 27001, GDPR certification, or another external compliance attestation.

    What does hold

    Questions about a specific environment get a direct answer instead of a badge.

Need to verify a boundary for your environment?

Describe the setup you have in mind and get a specific answer.

Ask a security question