Skip to content
brainplane home
How it works Compare Pricing Docs FAQ
How it works Film Compare Pricing Docs FAQ My account
My account Download
  1. Home
  2. Legal center
  3. Security
Legal center Terms of Service Terms in plain words Privacy Policy Cookie Policy Subprocessors Refund Policy Security Legal notice

On this page

1. Local first2. Your logins stay yours3. What brainplane does and does not do on its own4. Installs and downloads5. Signed and notarized6. Your account and licence7. How we build it8. Report a vulnerability

Legal center

Security

Version 1.0, in force from 9 October 2026.

1. Local first

  • brainplane keeps your topics, decisions, Inbox cards, receipts and settings on your Mac, in its own folder in ~/Library/Application Support.
  • The background service (brainplaned) listens only on your Mac: a local socket readable by your user only (mode 0600) and 127.0.0.1. It refuses requests whose Host or Origin header is not its own.
  • The local page needs a session that the Mac app opens for you. The session cookie is HttpOnly and SameSite=Strict, and every write needs a CSRF token.
  • The background service's own code opens no connection to the internet. The Mac app connects only for the reasons listed in the Privacy Policy section 4. With a paired phone, Mac or server, that includes the relay, which carries sealed messages it cannot read.

2. Your logins stay yours

  • brainplane never reads your agent passwords or tokens (for example Claude, Codex or Grok credentials), nor your browser cookies. To link sessions, it reads the Codex session index, the first metadata line of recent Codex session files and Grok session summaries. It does not read their messages.
  • You sign in to each agent through its vendor's own login, in Terminal.
  • If you use the built-in OpenAI voice engine, your API key is stored in the macOS Keychain, on this Mac only. It is never sent to the background service, the page, a log or us.

3. What brainplane does and does not do on its own

  • brainplane's own code never sends messages, pays, buys, deletes files or deploys. These limits are fixed in the code.
  • Each handoff it starts leaves a receipt. Spoken or typed requests always become a card first, and nothing runs before you press Run.
  • Before brainplane changes an agent's config file, it shows you the exact change, copies the current file to a backup and offers an undo.
  • Agent hooks fail open within 1 or 2 seconds, so brainplane never blocks your agents.
  • Before data is written to brainplane's log, a guard refuses secrets it detects and masks bank account numbers (IBAN).

4. Installs and downloads

  • Agent installs run only when you press Install or Update, using the vendor's official installer from a fixed list of hosts, over HTTPS. Each install runs without administrator rights and leaves a receipt.
  • Skill updates are fetched only when you press Check for updates, pinned to a reviewed version, and shown as a diff before they apply.

5. Signed and notarized

  • brainplane is distributed as a disk image from brainplane.app, outside the Mac App Store.
  • The app and the disk image are signed with an Apple Developer ID (team 3GPZ94WLHV), built with the hardened runtime, and notarized by Apple. macOS checks this when you open the app.
  • The download page lists the SHA-256 checksum of the current disk image.
  • To check your copy in Terminal: spctl -a -vv /Applications/brainplane.app should report "Notarized Developer ID" and team 3GPZ94WLHV.

6. Your account and licence

  • Sign-in uses a 6-digit code sent by email, valid 10 minutes, with a limited number of tries. We store codes and session tokens only as hashes, and licence keys encrypted.
  • The licence file on your Mac is signed by our server. The app checks the signature with a public key built into the app.
  • The site sends strict security headers. Google Analytics loads only after you press Accept in the cookie banner, and never on My account or Buy. Payment is on Stripe's hosted checkout, so card details never touch our pages.

7. How we build it

  • Every change runs the full test suite before release. Changes get a separate automated code review before they merge, with a security review for changes to authentication, the local server, the installer, the account service and the agent connections.
  • Dependencies are pinned in a lockfile. Open-source licences ship with the app.

8. Report a vulnerability

Please email hello@brainplane.app with the steps to reproduce, the version and the impact you see. Our contact details are also in https://brainplane.app/.well-known/security.txt.

What you can expect from us:

  • an answer within 5 working days;
  • updates while we work on a fix, and credit in the release notes if you want it;
  • no legal action against good-faith research that respects the rules below.

Rules for good-faith research:

  • test only on your own Mac, your own account and your own data;
  • do not access, change or delete other people's data;
  • do not run denial-of-service or social engineering tests against us or our providers;
  • give us reasonable time to fix the issue before you publish it. We suggest 90 days.

Out of scope: vulnerabilities in the agents themselves (Claude Code, Codex, Grok and others) or in third-party apps. Report those to their vendors.

When the law requires it, we report actively exploited vulnerabilities and severe incidents to the competent authorities, and we inform affected users.

The shared brain and control plane for your AI agents.

How it works Film Compare Pricing Docs FAQ Download My account Guides Glossary

© 2026 brainplane. Legal center · Terms · Privacy · Legal notice · Claude Code, Codex, ChatGPT and Grok are trademarks of their owners. brainplane is not affiliated with them.