OpenFolksDocs
Security

Security model

Boundaries that keep folks, credentials, and computers scoped.

OpenFolks is built around a local owner, explicit capabilities, and narrow process boundaries. Local-first is not risk-free. A folk with tool or computer access can still act on what you grant.

Core boundaries

  • The harness owns engine processes and listens on loopback.
  • The renderer receives configured-or-not credential state, not secret values.
  • Provider credentials are injected only into the process that needs them.
  • Risky actions become approval cards rather than implicit permission.
  • Local computer control is a separate opt-in and per-folk selection.
  • Cloud and VPS backends are validated before reuse.

Your part

  • Review approvals, especially shell commands, file writes, and actions in connected services.
  • Use dedicated environments for untrusted or destructive work.
  • Keep provider accounts and connected apps scoped to what that folk needs.
  • Keep OpenFolks and engine CLIs updated.

Report security issues through the repository's documented channel. Do not disclose them in a public issue before a fix is available.

On this page