Does FrontierStack send my passwords or secrets to AI services?
No. Anything bound for a cloud AI is protected on several layers — and the protection covers the AI Administrator, the search-palette AI, the MCP and HTTP control servers, Shortcuts, and the external CLI agents (Agent Jobs / Data Map).
- Always-on redaction. Before any text leaves your Mac, FrontierStack scrubs out secret values — every credential in its Keychain (SSH/sudo passwords, SaaS API keys, router/registrar secrets, AI keys), your linked password-manager secrets and
.envscript secrets — plus secret-shaped patterns (passwords, tokens, Bearer/AWS keys, private keys,user:pass@hoststrings) and usernames. A green note tells you when something was scrubbed. - Big red confirmations. Risky actions (exposing a service publicly, opening a firewall port, registering a domain, rebooting, installing software, overwriting files, data-changing SQL) pause for an explicit confirmation — nothing runs until you approve.
- Optional local-AI screening. If you have a local model (Apple on-device or Ollama), an extra check runs on your Mac to catch secrets/PII the patterns miss, and can warn, auto-redact or block the send — the check itself never leaves the machine.
- Local stays local. Apple on-device and local Ollama/LM Studio models send nothing off the Mac at all.
Read more in the in-app Help ▸ AI security & privacy.
Run it all from one Mac app.
FrontierStack installs, monitors and secures the whole stack — locally and across your fleet — from a single native macOS app.
Download FrontierStack