# Is it safe to let AI agents run on my Mac?

Agents like Claude Code and Codex can edit files and run commands with the permissions you give them. You stay safe with 3 habits: keep risky actions behind a human step, keep a record of every change, and keep secrets out of what agents read. brainplane adds stop cards, holds, receipts and a secret guard, and never sends, pays, deletes or deploys on its own.

Canonical: https://brainplane.app/guides/is-it-safe-to-let-agents-run-on-my-mac/

## What can go wrong

An agent acts with the permissions you grant it. With broad permissions it can delete files, push code, send an email or spend money through a tool. Most mistakes come from 3 places: an action nobody reviewed, a change nobody can trace, and a secret pasted into a prompt or a note.

## 3 habits that keep you safe

| Habit | In practice |
|---|---|
| A human presses the final button | Sending, paying, deleting and deploying wait for you |
| Every change leaves a trace | You can see what changed, who asked and when, and undo what can be undone |
| Secrets stay out of reach | No password, code or API key in notes or prompts |

## What brainplane does

- **Stop cards.** Sending, paying, deleting, deploying, creating accounts, buying paid plans and handling secrets always stop at a card for you. This rule is fixed in the code. No setting, rule or Autopilot level moves these actions to automatic.
- **Holds.** Every answer waits 2 seconds, or 5 seconds when the risk is high, so you can cancel it with Escape.
- **Receipts.** Every write brainplane stores leaves a receipt. The full log is plain text on your Mac.
- **Undo.** Some topic edits undo for 10 seconds. An answer that ran on automatic can be marked undone for 24 hours, which also moves that action back to ask.
- **Secret guard.** A password, a one-time code or an API key in a note is refused before it is stored, with a reminder to rotate it. IBANs are masked to their last 4 characters.
- **Read-only reviews.** Review and research runs are read-only: the read-only sandbox for Codex, a read and search tool list for Claude Code and Grok.

## What brainplane never touches

- Your agents' logins: it never reads Claude, Codex or Grok login files, tokens or browser cookies, and never asks for an agent API key.
- The network on its own: the local service listens on `127.0.0.1` and a private socket only, and checks the host and origin of every request.
- Your settings without a backup: every change to an agent's settings is shown first, backed up, and can be undone for 24 hours.

## What stays your call

brainplane's rule covers what brainplane does. Agents you run yourself keep the permissions you give them. A stop card asks an agent to wait for you; the agent's own settings decide what it can do. Keep broad permissions for work you can review.

## Questions

### Can brainplane send an email or pay for something?

Never on its own. An agent can prepare the email draft, fill the form up to the card field, or write the payment recap. You press the final button yourself.

### Where is my data?

On your Mac, in brainplane's own folder in `~/Library/Application Support`. Every change is 1 line in an append-only log. Your topics are not stored in a brainplane cloud. Sealed cards for a paired phone pass through the relay, which cannot read them.

### Is the app signed?

Yes. It is signed with an Apple Developer ID, with the hardened runtime, and notarized by Apple.

### How do I report a vulnerability?

Write to hello@brainplane.app with the steps to reproduce. We answer within 5 working days.
