Skip to content

HomeTrust

Every claim on this site, and where to check it.

Open source is a property you can verify, not a badge. This page lists what Cognia does with your work and points at the artefact that proves each statement.

01

Data boundaries

Where your work lives, and what a model call actually carries.

  • Local storage

    Conversations, artifacts, memory and settings are stored on your machine. The documentation describes the schema and the location.

    Learn more
  • Backup and export

    Your data can be exported and restored in a documented format — the test for whether it is really yours.

    Learn more
  • What reaches a model

    A call carries the prompt and the context attached to it, to the runtime you chose. The provider documentation states which one that is.

    Learn more
02

Permission and record

What stops before it acts, and what remains afterwards.

  • Approval checkpoints

    Actions that leave the project — pushing, calling an external tool, writing elsewhere on disk — name themselves and wait.

    Learn more
  • Capability declarations

    Plugins and tools can only reach what their manifest declares, and the catalog of capabilities is public.

    Learn more
  • Execution model

    Plugin bundles execute in the host page through indirect eval. Declared capabilities gate Cognia APIs, but ambient browser globals remain available.

    Learn more

A task crosses named boundaries.

The useful question is not whether an AI workspace is abstractly safe. It is where data lives, what leaves, which action waits, and what remains to inspect.

  1. Local workspace

    Threads, settings, memory, artifacts, and project state begin in the desktop workspace and its documented local stores.

    Learn more
  2. Selected runtime

    Only the prompt and attached context needed for a call go to the local or remote model runtime selected for that task.

    Learn more
  3. Approval boundary

    A gated tool action describes its target and waits at the boundary before it changes external state.

    Learn more
  4. Durable record

    Tool events, agent traces, errors, and run timing stay attributable to the task so behavior can be reviewed after execution.

    Learn more

Claim and source

Nothing in this table is maintained by hand. Each row points at the artefact the claim is read from.

ClaimSource
The application is licensed AGPL-3.0-or-laterLICENSE in the repository
The source is public and completeThe repository itself
Desktop builds are produced by a signed workflowThe release workflow in the repository
Published releases and supported platformsGitHub Releases, read at build time
How each subsystem behavesThe architecture decision records