Does FrontierStack send my passwords or secrets to AI services?
No. Anything bound for a cloud AI is protected on several layers; and the protection covers the AI Administrator, the search-palette AI, the MCP and HTTP control servers, Shortcuts, and the external CLI agents (Agent Jobs / Data Map).
- Always-on redaction. Before any text leaves your Mac, FrontierStack scrubs out secret values; every credential in its Keychain (SSH/sudo passwords, SaaS API keys, router/registrar secrets, AI keys), your linked password-manager secrets and
.envscript secrets; plus secret-shaped patterns (passwords, tokens, Bearer/AWS keys, private keys,user:pass@hoststrings) and usernames. A green note tells you when something was scrubbed. - Big red confirmations. Risky actions (exposing a service publicly, opening a firewall port, registering a domain, rebooting, installing software, overwriting files, data-changing SQL) pause for an explicit confirmation; nothing runs until you approve.
- Optional local-AI screening. If you have a local model (Apple on-device or Ollama), an extra check runs on your Mac to catch secrets/PII the patterns miss, and can warn, auto-redact or block the send; the check itself never leaves the machine.
- Local stays local. Apple on-device and local Ollama/LM Studio models send nothing off the Mac at all.
Read more in the in-app Help ▸ AI security & privacy.
Run it from your Mac.
FrontierStack installs, monitors and secures services on this Mac and on linked servers.
Download FrontierStackApple notarized · Safe & secure · macOS 13 Ventura+
