The working system stays local.
Your active repository, technical index, project graph, and Kaplira run records remain on your computer.
Trust / Data boundaries
Kaplira governs coding-agent work without pretending every part of the stack is under its control. Here is what stays local, what can leave, and where the boundary ends.
Data flow
Your active repository, technical index, project graph, and Kaplira run records remain on your computer.
When a run uses an external provider, Kaplira materializes task-specific context for that selected route. The provider's own data terms still apply.
Standard exports omit diff bodies, source contents, prompts, command output, credentials, and secrets. A detailed export may include diffs when you explicitly select it.
Run permissions
A governed run can carry explicit permissions and architecture scope. The structured contract is the authoritative boundary used by pre-edit and review gates.
Where Kaplira stops
Each limit a reviewer should know before relying on Kaplira, paired with what does hold.
Not claimed
Kaplira does not replace a model provider's privacy or security terms.
What does hold
Only the task context materialized for a run you route to that provider can leave your device.
Not claimed
Current receipts do not claim a cryptographic signer or independent authenticity proof.
What does hold
A receipt checksum checks that the recorded content is consistent.
Not claimed
Writes made entirely outside a governed Kaplira path cannot always be prevented in advance.
What does hold
Later diff capture and review can surface them.
Not claimed
Kaplira does not currently claim SOC 2, ISO 27001, GDPR certification, or another external compliance attestation.
What does hold
Questions about a specific environment get a direct answer instead of a badge.
Describe the setup you have in mind and get a specific answer.