Files
gnome-jarvis/docs/security-privacy.md
T
snxraven a097adf4eb
Rolling release / release (push) Successful in 8m31s
Updates
2026-09-13 22:24:14 -04:00

65 lines
2.8 KiB
Markdown

# Security and privacy
The default posture is local inference, explicit writes, and fail-closed
computer use. No telemetry or cloud inference is required. Model endpoints
stay on localhost. Public `web_search`, `google_search`, `fetch_page`,
`web_fetch`, `wiki_search`, `hn_search`, `code_search`, and `browser` are allowed
by default without a confirmation prompt and without extra API keys. They run in
a Jarvis-owned Chromium window. Private, loopback, and metadata URLs are
blocked before the browser starts. There is no SearXNG dependency. Shell
commands that open public HTTP (curl, wget) remain blocked by the runtime; use
the web tools instead.
```mermaid
flowchart TD
R[User request] --> P{Permission gate}
P -->|read| X[Execute locally]
P -->|write / dangerous| C{Explicit confirmation?}
C -->|yes| X
C -->|no| B[Block and explain]
X --> A[Audit metadata]
X --> D[Return result]
L[Lock screen] --> K[Revoke CU + webcam + mute HUD]
```
## Protected assets
- Microphone audio remains in a RAM ring buffer unless transcript retention is
explicitly enabled.
- Screen frames remain in memory or temporary storage and are wiped on
computer-use revoke by default.
- Webcam stills stay under `/tmp/jarvis-webcam` and are wiped on camera
revoke, lock screen, cancel, or `WipeComputerTraces()`. Camera access is
off by default and needs Settings plus Allow now.
- Computer-use audit logs store action metadata and screenshot hashes, not
screenshots.
- Voice references, memory, and model caches are user-owned files.
- QVAC binds to localhost; bearer tokens, when used, come from user-owned
configuration and are not logged.
## Filesystem access
Path tools default to the Jarvis workspace (`~/.local/share/jarvis-qvac` when
installed). Settings can widen that to your home directory or the entire
filesystem. This is still your user account: Jarvis does not gain root, and
writes plus shell commands still go through the confirmation gate.
## Computer-use controls
Computer use requires a spoken or HUD grant, shows a visible cursor/target, and
stops on revoke, Escape, lock screen, or grant expiry. It refuses password
fields, dangerous actions without confirmation, and actuation when the portal
or EIS backend is not ready. Legacy input is opt-in.
Camera access is a separate fail-closed grant. Enable it in Settings, press
Allow now, then the agent may call `webcam`. Revoke, lock screen, cancel, and
grant expiry wipe captured stills.
## Threat model boundaries
The daemon assumes the local user account and installed desktop libraries are
trusted. A malicious local process with access to the user's session bus or
filesystem is outside the protection boundary. Keep the repository and model
cache user-owned, use a restrictive token file mode, and avoid running the
daemon as root.