GrantTap legal and support
Security
Last updated:
GrantTap Personal is a native end-to-end encrypted control channel for local coding-agent sessions. It is not a model proxy, terminal, identity service, or universal agent security layer.
What remains local
- Source repositories and workspaces.
- Provider credentials and model traffic.
- Readable prompts, commands, replies, attachments, and decisions except on authorized endpoints.
What the relay can see
- Opaque room and mailbox identifiers, sender/recipient roles, timing, expiry, message size, IP address, and APNs routing metadata.
- Authenticated nonce and ciphertext.
- No browser approval, browser pairing, vault, or plaintext rendering endpoint exists in the Personal relay.
Keys and isolation
Pairing uses an independent transfer key that never leaves the QR/manual token. Authorized endpoints create and store device and per-task keys locally. One task key cannot decrypt another task.
- Every WebSocket and push registration route requires the random room credential.
- Offline ciphertext queues are bounded, expiring, and retained until decrypt acknowledgement where supported.
- APNs receives a generic wake with no task content.
Scope and reporting
GrantTap reduces exposure of its control channel; it cannot make a provider, MCP server, skill, CLI, operating system, or user-approved command safe. Use provider controls and review risky actions.