alden

Security model

What Alden protects, against whom, and how. For reporting a problem, see SECURITY.md.

What's worth protecting

Who might try

How Alden handles it

Tokens. Your GitHub token lives in the OS keychain, or, where there's no keychain, a file only your user can read. Alden never logs it, never sends it anywhere but GitHub, and never puts it in a prompt. Model keys come from the provider's own configuration and stay with its SDK.

alden ui. The server listens on 127.0.0.1 only. Every API call must carry a random session key, which reaches the browser in the link's #fragment (never sent to a server or in a Referer) and is compared in constant time. The server also rejects any Host or Origin that isn't its own, which stops other websites, including through DNS rebinding. It sends no CORS headers, so other pages can't read its responses. Pages get a strict Content Security Policy (only Alden's own scripts, styles and images, plus GitHub avatars), can't be framed, and send no referrer.

PR content.

Secrets in diffs. Before a prompt is sent, anything that looks like a credential is replaced with a placeholder that keeps only its kind and length (see Privacy and data). Detection is heuristic, so use --no-llm for changes you know contain secrets, and rotate any secret that was committed.

Your data. Nothing goes to Alden's developers except anonymous usage stats, and only if you opt in (Usage stats). Feedback, memory, spend and settings stay in ~/.alden; alden feedback --export leaves out repo names, paths and notes unless you pass --full.

Supply chain. Dependencies are audited before each release (pnpm audit), lockfiles are committed, and releases are built in CI from a tag, with macOS binaries signed and notarized.

Known limits