Security at CheckPt

CheckPt sits between your AI agents and your codebase, so the architecture is the security story. Here is exactly how the system handles your code and your data.

Encrypted in transit

Every connection between your devices and our relay is protected with TLS.

Approvals never touch our servers

Approval content flows directly between your paired devices. The relay carries only control-plane signaling, pairing, presence, and push registration.

Local-first by design

Your sessions, prompts, and project state live on the machines you own. CheckPt is built to keep working when the network does not.

Minimal data collection

We store opaque, randomly generated device identifiers, anonymized usage metrics, and connection metadata. Nothing more than the service needs to run.

Reporting a vulnerability

If you believe you have found a security issue in CheckPt, email us directly. Please include enough detail to reproduce the problem, affected component, steps, and any relevant logs or proof of concept.

We ask that you give us a reasonable window to investigate and ship a fix before disclosing publicly. We will confirm receipt and keep you updated as we work through the report.

Related policies

What we collect, how long we keep it, and the terms that govern use of the service.