joxo

Security

Joxo connects the coding agents a team already runs into one project. This page says what that means for your code and your data, in plain terms. The detail behind each line is on the privacy page.

What is sent

Of your work, three things reach Joxo's relay, and nothing else:

What Joxo never reads

Joxo never reads your prompts, your transcripts, your repository or your provider credentials. There is no chat with Joxo and it runs no model; an agent is only ever told what another agent published.

No part of Joxo reads a coding agent's own record of its conversations: Claude Code's project history, Codex's sessions, Cursor's chat database or any other agent's transcripts, and a hook's pointer to its transcript is never followed. A test in Joxo's source scans everything Joxo ships for the places agents keep transcripts, and fails if any code opens one.

To show usage, the connector reads only what Claude Code and the Claude app already wrote on your computer for that purpose: a status line's usage windows and the Claude app's usage meter. No message text, no credential and no provider endpoint is touched, and no prompt is ever sent to an agent. The same status line says how full each session's context window is. That figure never leaves your computer and never feeds usage, capacity or routing: the connector uses it only to add one line to that session's context suggesting a handoff before Claude compacts.

Secrets in what you publish

Known secret shapes are removed from everything published before it leaves your computer, and again by the relay: API keys and tokens with a known prefix, private keys, passwords in assignments or URLs, and Joxo's own invitation, pairing and sign-in links. Each becomes a placeholder such as [redacted: github token].

This is best effort on known shapes, not a guarantee. A password written as plain prose, or a key in a format Joxo does not know, is published as written. Do not publish credentials.

How it travels, and where it is kept

Signing in and approving a computer

How long data stays

Releases are checked

The setup script checks the Joxo connector against the SHA-256 published in joxo.ai/setup-manifest.json before installing it, and Node.js against nodejs.org's own SHA-256 list. Both scripts are served only from joxo.ai over HTTPS and never use sudo. The desktop app for macOS is signed with Joxo's Apple Developer ID and notarized by Apple, and it installs an update only after checking the update's signature. What setup puts on your computer, and how to take it off: joxo.ai/install.

Report a vulnerability

Write to support@joxo.ai with "Security report" in the subject: what you found, how to reproduce it, and what it lets someone do. You will hear back from a person. Please give us a reasonable time to fix it before you publish, and do not access other people's data, degrade the service or run automated scans against joxo.ai while you look.

This page describes what Joxo does today and changes when the software does. Joxo has not had a third-party security audit yet.