SECURITY & DATA

Explain the data flow before asking for trust.

SciFound is a local-first desktop workbench, but local-first does not mean every action is offline. Storage, network calls, and release trust are explained separately.

01

Local project

Files, conversations, and project memory stay in the workspace you choose by default.

02

Explicit action

Model calls and enabled network or sharing actions transmit the content required for that operation.

03

Visible source

The interface should show the active model source and tools.

01

Project access boundary

The desktop host validates file operations against the current project scope.

02

Document reading bounds

Built-in readers bound input size, output, and concurrency.

03

Recoverable failures

Missing dependencies, connection errors, and rejected access remain visible.

04

Release integrity

Update manifests, installer checksums, and platform signatures are verified separately.

DISCLOSURE

Found a security issue?

The public support and security contact still require confirmation from the operating entity. Until then, this page is not a formal disclosure channel.