maestrly.

Security

Local-first, not local-only.

An MIT-licensed 0.x source preview. Workspace state stays local; selected providers and tools receive the context you authorize. Official binaries, when available, exist only on tagged GitHub Releases.

Data flow

Clear boundaries for every turn.

The exact provider payload depends on the model and tools you use. Maestrly does not claim that cloud inference stays on-device.

Your device

  • Repository and project state
  • Local SQLite database and notes
  • Git worktrees and local tool execution
  • Protected provider credentials
  • Orchestration and permission decisions
Direct provider connection

Chosen AI provider

  • Your prompt
  • Context required for the request
  • Relevant attachments
  • Tool results returned to the model

Credentials stay protected

App-managed credentials use Electron safeStorage; persistence fails closed if OS encryption is unavailable. Provider CLIs and Git credential helpers manage their own independent stores. Provider authentication does not create a Maestrly account.

Tools stay under your control

Tool policies can allow, deny, or ask before an action. Workspace scope and operating-system permissions remain meaningful boundaries, especially for terminal, files, browser, and connected MCP tools.

Local diagnostics, no telemetry

The app has no analytics, telemetry, or automatic crash/log upload. Diagnostics remain local unless you deliberately share them. Remove secrets, private paths, and identifying content first. Providers, websites, and enabled tools still process requests under their own policies.

Local export and reset

Export supported app data before an explicit reset; repositories and worktrees are preserved. Exports exclude credentials and repository files. There is no Maestrly account to delete. Backups, provider records, and independent credential stores must be managed separately.

Report vulnerabilities privately

To report vulnerabilities, follow the confidential process in SECURITY.md in the public repository. Support is provided on a best-effort basis.

The full policy details

Provider practices are governed by their own terms and privacy policies. A supported integration does not imply partnership or affiliation.