Skip to content

Security

Your computer. Your approval.

Bots work in a folder on your disk and ask before they change anything. Here is what protects that today, what is not done yet, and how to report a flaw.

Three principles

  • Work stays on your computer.

    Bots, threads, files and memory live in a folder on your disk. The app sends no telemetry.

  • Every change asks first.

    By default, edits, commands, pushes and messages wait for a yes. Each decision is recorded, whether a person or a rule made it.

  • The API keeps no prompts.

    It records each call’s model, tokens and cost. Never the prompt and never the reply.

Where it runs

Three places, and what each of them holds.

  • The Lobstack app

    On your computer: Windows, macOS or Linux.

    Each workspace is its own database file. Credentials sit beside them in an encrypted vault.

    What leaves your machine →
  • The Lobstack API

    On Vercel, with Postgres on Supabase.

    Your org, hashed keys, and each call’s metadata and cost. Nothing of yours runs between requests.

    Tenant isolation →
  • Phone approvals

    Through lobstack.ai, once you pair a phone.

    Cards are sealed on your computer and lobstack.ai can’t read them. Payments can’t be approved from a phone.

    The approval gate →

Secrets and keys

How each one is kept. How API keys are stored has the detail.

SecretHow it is kept
Connector credentialsAES-256-GCM in the app’s vault. The key is kept in your system’s credential store, or in an owner-only file when that store is unavailable.
Lobstack API keysStored as a SHA-256 hash. Shown once, scoped and revocable.
Your provider keysAES-256-GCM, bound to your org and to that provider. Only the last four characters are ever shown.
Connector sign-insThe token passes through lobstack.ai encrypted, and is deleted once the app collects it.
Phone answersActed on only after your computer checks the phone’s signature.

Access and audit

Who can do what in your org, and the record of what they did.

  • Four roles

    Owner, admin, member and viewer. Viewers can look but not change anything.

  • The starter approves

    On a shared bot server, only the person who started a run can approve it. Anyone can deny or stop it.

  • An audit log

    Who changed keys, members, invites and webhooks, with CSV and API export. On Agency and Scale; Scale also sends each record to your webhooks.

  • Every approval kept

    In the app, each decision notes whether a person or a rule made it, and when it came from a phone.

Prompt injection

A page or a file can carry text aimed at the model. The approval gate stands between that text and your files, and three checks help you notice it.

In place

  • Tool output reaches the model labelled as untrusted data, and a page can’t close the label early.
  • Override phrasing, such as “ignore previous instructions”, is flagged on the step.
  • A call unlike the ones you approved before is marked on its approval card.

What it does not stop

  • A model persuaded anyway. Labels make it less likely, not impossible.
  • Paraphrase, other languages or encoded text. The flag catches formulaic attempts only.
  • A harmful call to a familiar target, such as the repository a bot always pushes to.
  • Labelling on the GitHub Copilot engine, which formats tool output itself.

Data handling

What is sent to model providers?

Your prompts, a bot’s instructions and anything a tool reads, to the provider serving that call and no other. On the default engine they pass through the Lobstack API; on Copilot or your own key they go straight there.

Do you train on my data?

No. Lobstack does not use your prompts, replies or other content to train models. Each provider has its own policy for what it receives.

What do you keep about a call?

The request id, the models asked for and served, tokens, cost, status and latency, and the key and org it was billed to. Not the prompt and not the reply.

How long do you keep it?

Request-level rows follow your plan’s history window. Billing records are kept for seven years and platform logs for ninety days. The full schedule is in Privacy §8.

How do I delete my data?

In the app, delete the workspace; it is a folder on your disk. For your account, ask us and we delete it within 30 days, and from backups within 90. There is no self-serve deletion yet; Privacy §8 says how to ask.

Who else processes it?

Vercel and Supabase host the site and the database, Stripe takes payments, Airtable holds sales enquiries, and the model providers serve calls. Each is named in Privacy §5 and §6.

What does the app send you on its own?

An update check carrying your platform, architecture and version. No telemetry, analytics or automatic crash reports; a report goes only when you press Send.

Not yet

What a security review may ask for that Lobstack does not have today. Controls, by state has the rest.

No SOC 2 audit
No audit has been performed, and there is no report to send.
No penetration test
No third party has tested Lobstack yet.
Installers not code-signed
Windows warns on the first run. macOS asks once, in Privacy & Security.
No single sign-on
There is no SAML or OIDC sign-in in the product.
No two-step sign-in
A Console account has no second factor yet.
One region
One database and one deployment, in the US, with no residency commitment.
Network jail on Linux only
On Linux, a command in a repository reaches only the hosts you allow. On macOS and Windows it is not fenced.
One trust level on a shared server
Everyone with access sees every thread and can use every connector.

Report a vulnerability

Report it privately on GitHub, where only the Lobstack team can see it.

Report on GitHub

Please don’t open a public issue for anything exploitable.

In scope
lobstack.ai, the Lobstack API, Console, the Lobstack app, and the public SDK, CLI and MCP repositories.
Out of scope
Denial of service, spam, social engineering, and attacks that need your computer already compromised.
What to send
What you found, how to reproduce it and what it lets someone do. For the API, add the call’s x-lobstack-request-id.
Safe harbour
Good-faith research is welcome. Test only your own accounts, keep no one else’s data, and don’t degrade the service, and we won’t take legal action over it.
Disclosure
Please stay quiet until a fix ships or 90 days have passed since your report, whichever comes first. We’ll agree the date with you.
Our reply
We’re a small team. We aim to reply within three business days and to assess the report within ten.
Rewards
There is no bug bounty. With your permission, we credit you in the published advisory.

Your security review.

Talk to us about what it needs. Where the answer is no, you’ll hear no.

Lobstack for teams