← Back to Slate Security

Security.

Local-first by construction

Conversations, memory, files, generated images, dictation and code all run on device. There is no Slate account, no server-side history, and no analytics or crash reporting. The only network calls are model downloads you start, the one-time Pro licence check, and any cloud connector you explicitly enable with your own key.

Open source you can audit

The engine behind Slate is public under the MIT licence. You do not have to trust a marketing claim: read the code, build it yourself, and watch the network. github.com/Lange-Co-Consulting/slate-engine.

Secrets stay in the Keychain

Cloud API keys and the Pro licence key are stored in the macOS Keychain. They are never written into a settings export and never sent anywhere except the service they belong to.

Payments

Purchases run through our Merchant of Record. We never see or store your card details; payment data is handled by the payment provider under its own security program.

Reporting a vulnerability

If you believe you have found a security issue, please email info@lange-co-consulting.de with steps to reproduce. Please give us reasonable time to fix an issue before disclosing it publicly. We are grateful for responsible reports and will credit you if you would like.