Skip to content

Security at CheckPt

CheckPt sits between your AI agents and your codebase, so the architecture is the security story. Here is exactly how the system handles your code and your data.

End-to-end encrypted

Prompts, approvals, session output, and session titles are sealed on your devices and readable only there — with TLS protecting every connection underneath.

Our relay can't read your content

Approval content is sealed before it leaves your machine. The relay routes and stores only ciphertext — plus the signaling, pairing, presence, and push registration it needs to run — and holds no key that can decrypt any of it.

Local-first by design

Your sessions, prompts, and project state live on the machines you own. CheckPt is built to keep working when the network does not.

Minimal data collection

We store minimal operational data: device and session identifiers, timestamps, connection metadata, the names you give your devices and projects, your repository owner and name, and anonymized usage metrics. Your session content is sealed on your devices and unreadable to us.

Reporting a vulnerability

If you believe you have found a security issue in CheckPt, email us directly. Please include enough detail to reproduce the problem, affected component, steps, and any relevant logs or proof of concept.

We ask that you give us a reasonable window to investigate and ship a fix before disclosing publicly. We will confirm receipt and keep you updated as we work through the report.

Related policies

What we collect, how long we keep it, and the terms that govern use of the service.