Security
The security policy for every DeskMind repository is deskmind-ai/.github/SECURITY.md. This page summarises it; the file is the source of truth.
Report privately
Section titled “Report privately”Please do not open a public issue for a security problem.
- Open the Security tab of the affected repository on GitHub.
- Choose Report a vulnerability.
If you cannot use GitHub, email security@deskmind.dev. We aim to acknowledge reports within 7 days.
What we care about most
Section titled “What we care about most”- Anything that could send screen contents or user data off the machine unexpectedly.
- The desktop driver (Hands) acting outside the requested task or sandbox.
- Secrets or personal data in released files.
When you prepare a report
Section titled “When you prepare a report”- Use made-up data and a disposable folder, as for any bug report.
- Do not attach real screenshots, traces or documents from your own apps. Describe them, or reproduce the problem with synthetic data.
What runs where
Section titled “What runs where”To judge whether something is a leak, it helps to know what is supposed to use the network. By default, inference runs on your Mac; model downloads and the apps DeskMind operates use the network, and an optional remote escalation tier receives the requests sent to it. See Architecture: what runs locally.