Security at CheckPt
CheckPt sits between your AI agents and your codebase, so the architecture is the security story. Here is exactly how the system handles your code and your data.
End-to-end encrypted
Prompts, approvals, session output, and session titles are sealed on your devices and readable only there — with TLS protecting every connection underneath.
Our relay can't read your content
Approval content is sealed before it leaves your machine. The relay routes and stores only ciphertext — plus the signaling, pairing, presence, and push registration it needs to run — and holds no key that can decrypt any of it.
Local-first by design
Your sessions, prompts, and project state live on the machines you own. CheckPt is built to keep working when the network does not.
Minimal data collection
We store minimal operational data: device and session identifiers, timestamps, connection metadata, the names you give your devices and projects, your repository owner and name, and anonymized usage metrics. Your session content is sealed on your devices and unreadable to us.
Reporting a vulnerability
If you believe you have found a security issue in CheckPt, email us directly. Please include enough detail to reproduce the problem, affected component, steps, and any relevant logs or proof of concept.
We ask that you give us a reasonable window to investigate and ship a fix before disclosing publicly. We will confirm receipt and keep you updated as we work through the report.
Related policies
What we collect, how long we keep it, and the terms that govern use of the service.