Security and trust
Draft pending counsel review · Updated October 8, 2026
Provider traffic and conversation privacy
Your local proxy forwards credentials to the selected provider. Leash local mode does not store provider keys. Neither mode stores prompts, response text, tool arguments or source code. Parsing occurs in memory; retained data is usage metadata and request hashes. Agent-generated conversation logs remain under your control. Report scans retain aggregates only, and shared reports reveal numbers after explicit consent.
Local enforcement and its boundaries
The proxy binds to loopback by default and requires a random local token. Browser-origin requests to the proxy are denied. SQLite transactions reserve estimated cost before requests and preserve pending reservations through crashes. Kills block new requests and abort active streams; a provider may still bill work already processed. Traffic that bypasses the proxy is outside Leash’s control. The local machine owner is trusted and can edit files or turn off enforcement.
Identity and workspace isolation
Local passwords use salted scrypt hashes. Opaque API, browser and CLI tokens are hashed in Postgres, expiring and revocable. Clerk JWTs are verified when Clerk is configured. Device authorization requires explicit user approval. Normal authenticated API requests run in transactions with a non-owner, non-BYPASSRLS database role and workspace-scoped RLS policies. Authentication, workspace transitions, verified billing webhooks and explicitly shared report reads use narrowly validated privileged queries. Table owners still bypass RLS; database administrator credentials must never be distributed to end users.
Secrets and browser protections
Staging and production refuse a missing, short or known development service token. Web session cookies are HttpOnly, SameSite and Secure in protected deployments. Mutations check the configured public origin. Security headers prevent framing and MIME sniffing; HTTPS deployment adds HSTS. CSP requires a fresh per-request nonce for scripts and blocks untrusted inline JavaScript. Inline styles remain allowed for application charts and the Clerk rendering integration. Saved webhook destinations use AES-256-GCM encryption; operators must preserve and restrict the encryption key. Tokens and request bodies are omitted from metrics logs.
Hosted operation and payments
The staging package deploys the dashboard, control API and database behind HTTPS, including a separate hosted provider gateway. Hosted requests and shared-mode devices reserve budgets atomically through one authoritative Postgres ledger. Shared admission fails closed when the control plane is unavailable. Devices still configured for local mode enforce independent caps. Virtual keys are hashed, scoped and revocable; optionally stored provider credentials use random per-key encryption envelopes authenticated to their workspace. The master encryption key stays outside the database. BYOK passthrough keys are forwarded in memory and never stored. The configured Polar integration checks webhook signatures against the raw request body, subscription bindings are validated, and duplicate/out-of-order events are handled. Billing convenience limits do not turn off protection. Live OAuth, provider traffic and payment acceptance must be verified in the operator’s configured environment.
Email security
Email provider credentials remain on the control API. Account links and queued message content are encrypted at rest; confirmation and password-reset tokens are short-lived and single-use. Resetting a local password revokes existing browser and CLI login sessions. Report delivery rechecks the recipient’s verified address, membership and preferences before sending. Unknown provider outcomes are held for operator review instead of automatically sending a duplicate.
Operations and disclosure
Operators should restrict private service/database networks, rotate secrets, maintain encrypted backups and test restore, monitor health endpoints and investigate unexpected 401/403/503 responses. Leash has not completed a SOC 2 certification or an independent penetration test. Report a suspected vulnerability privately to hello@useleash.dev with reproducible details and affected versions. Avoid accessing another workspace’s data or interrupting service. We will coordinate remediation and disclosure; no bounty payment is promised.