Skip to main content

Local execution

On the app surfaces — Desktop, terminal (TUI), and VS Code — the agent runs on your machine. This page looks at that model from a security standpoint: what actually leaves the device, what stays local (and under which conditions), and what content redaction covers. For the full mental model, see Local execution & privacy under Concepts.

What leaves the device​

Only the prompt content — what the model needs to "read" in order to answer — is sent, through the product's single egress point. In practice:

  • Your message.
  • Excerpts of files the agent decided to place into the context for the task.
  • Minimal request metadata (model, generation parameters).

What does not leave through the local surfaces:

  • The files themselves. The agent reads the content on disk and transmits only what is needed; there is no file upload.
  • Your session and your memory. History, actions, and memory notes stay on disk (see below).
  • Tokens and credentials. Your authenticated session's credentials are never sent to the model, and any token that appears in the prompt body is redacted; vendor keys never pass through the client.
A single egress point to the model

There is no alternative route to the model. Concentrating all egress at a single point lets the organization enforce authentication, policy, and metering in one place.

What stays local​

DataWhere it livesEncrypted?
Sessions / historyLocal project files.No — readable files.
Project memory<project>/.imaginne/memory/*.md.No.
Skills~/.imaginne/skills/ (global) and <project>/.imaginne/skills/ (project).No — except the local_protected skill bundle, which is verified and extracted into a temporary folder.
Configuration and session token~/.imaginne/config.yaml (permissions 0600).No, but with restricted file permissions.
Generated artifactsProject output folder (by default outputs/).No.
Local state is not encrypted

Sessions and memory sit in readable files on your disk — the same posture as any local project. Security at rest is your machine's: treat it the way you already treat your source code and your documents. On shared machines, consider turning off the TUI's local persistence with IMAGINNE_TUI_LOCAL_STORE=off.

Content redaction​

Before sending the content to the model, Imaginne applies a content checker that recognizes known sensitive patterns and replaces them with placeholders:

  • Emails and phone numbers.
  • National IDs (CPF/CNPJ) and card numbers.
  • Session tokens.
  • Cloud keys and PEM private keys.

The text matching these patterns is not logged. Treat redaction as a layer of defense, not as an absolute guarantee:

  • It covers recognized patterns, not any arbitrary secret (for example, an internal identifier with no fixed format may slip through).
  • It reduces accidental leakage; it does not replace good judgment when pasting highly sensitive data.

The web chat exception​

Browser chat installs nothing, so the agent runs on Imaginne's servers. There, the session content travels and is processed on the server, and the session is persisted there (tied to the organization and the user). It is the right option for quick, install-free access, but it does not meet a "nothing leaves the machine" requirement. For that, use Desktop or the TUI.

What this guarantees for the organization​

  • File sovereignty. On Desktop/TUI/VS Code, files are not sent; only the content the model needs travels.
  • A single egress point. All model traffic flows through a single egress point, where the organization enforces credentials and metering.
  • A smaller exposure surface. With no file upload and with redaction of known secrets, the risk of accidental leakage drops — while remaining a shared responsibility.

See also​