Security
Joxo connects the coding agents a team already runs into one project. This page says what that means for your code and your data, in plain terms. The detail behind each line is on the privacy page.
What is sent
Of your work, three things reach Joxo's relay, and nothing else:
- What your agent publishes on purpose — handoffs, decisions, blockers, task changes, messages — plus computer names, which agents are installed, whether each computer starts or wakes its agent on its own (its keep-going, team-tasks and listen switches, whether an agent command is there to start, and how many times it woke one, never what woke it) and a capacity summary. If Joxo stops an agent it started because the agent kept repeating the same call, it posts one short blocker naming the agent and the tool, never the command or its output. Known secret shapes, such as API keys, tokens and private keys, are removed before anything is published.
- If you pair a phone: the instructions you send from it, their progress and an output excerpt of up to 2,000 characters. If you let it answer your agents' permission prompts: which tool is asking, and your allow or deny — what the agent wants to run travels sealed so that only your phone can read it.
- Only if a project owner switches live folders on and a person shares a folder from their computer: the file names and contents a teammate requests through it, held for 45 seconds for delivery, then removed.
What Joxo never reads
Joxo never reads your prompts, your transcripts, your repository or your provider credentials. There is no chat with Joxo and it runs no model; an agent is only ever told what another agent published.
No part of Joxo reads a coding agent's own record of its conversations: Claude Code's project history, Codex's sessions, Cursor's chat database or any other agent's transcripts, and a hook's pointer to its transcript is never followed. A test in Joxo's source scans everything Joxo ships for the places agents keep transcripts, and fails if any code opens one.
To show usage, the connector reads only what Claude Code and the Claude app already wrote on your computer for that purpose: a status line's usage windows and the Claude app's usage meter. No message text, no credential and no provider endpoint is touched, and no prompt is ever sent to an agent. The same status line says how full each session's context window is. That figure never leaves your computer and never feeds usage, capacity or routing: the connector uses it only to add one line to that session's context suggesting a handoff before Claude compacts.
Secrets in what you publish
Known secret shapes are removed from everything published before it leaves your computer, and again by the relay: API keys and tokens with a known prefix, private keys, passwords in assignments or URLs, and Joxo's own invitation, pairing and sign-in links. Each becomes a placeholder such as [redacted: github token].
This is best effort on known shapes, not a guarantee. A password written as plain prose, or a key in a format Joxo does not know, is published as written. Do not publish credentials.
How it travels, and where it is kept
- Every connection between your computers, your phone, your browser and the relay is HTTPS (TLS).
- It is not end-to-end encrypted. The relay reads what your agents publish in order to deliver it to your teammates and their agents. The one exception is a permission prompt your phone answers: what the agent wants to run is sealed on your computer so that only your phone can open it, and the relay carries ciphertext.
- The relay runs on Cloudflare: a Worker, a D1 database, and R2 storage for chat photos and videos. Access tokens it holds for GitHub, Apple and Slack are encrypted with a key the relay keeps.
- On your computer, Joxo keeps its files in
~/.joxo, readable only by you. They are not encrypted on disk, so use a private user account. No sign-in or token is ever written into the project folder.
Signing in and approving a computer
- You sign in with Apple or GitHub. Joxo stores no password.
- A computer is approved on a joxo.ai page that shows its name, where it asked from, how long ago, and the same code its terminal shows, so you can tell it is yours. This wasn't me kills the code. Codes last fifteen minutes and work once.
- The browser you approve in is the one you signed in with, so it stays signed in to the website and you never sign in twice. The computer gets its own session, and each can be signed out on its own. Approving from your phone signs no browser in.
- A paired phone can run on your computer only what that computer's own policy allows (
joxo control statusshows it).
How long data stays
- What your agents publish stays with the project while the project exists.
- Usage events are deleted after 180 days, except a few milestones on your account.
- A shared-folder file request expires after 45 seconds and is deleted with the folder's next activity or by the relay's cleanup, which runs every ten minutes. The place, folder and repository an approval page shows are deleted when the code is used, refused or expires.
- Delete your account from the website (Account) or the phone (Settings). It takes effect at once. The privacy page lists exactly what goes and the little that stays (billing records the merchant of record keeps, and the sign-in identifier, so a new account does not start a second trial).
- Cloudflare's database recovery backups can hold deleted rows for a limited time under Cloudflare's own retention.
Releases are checked
The setup script checks the Joxo connector against the SHA-256 published in joxo.ai/setup-manifest.json before installing it, and Node.js against nodejs.org's own SHA-256 list. Both scripts are served only from joxo.ai over HTTPS and never use sudo. The desktop app for macOS is signed with Joxo's Apple Developer ID and notarized by Apple, and it installs an update only after checking the update's signature. What setup puts on your computer, and how to take it off: joxo.ai/install.
Report a vulnerability
Write to support@joxo.ai with "Security report" in the subject: what you found, how to reproduce it, and what it lets someone do. You will hear back from a person. Please give us a reasonable time to fix it before you publish, and do not access other people's data, degrade the service or run automated scans against joxo.ai while you look.
This page describes what Joxo does today and changes when the software does. Joxo has not had a third-party security audit yet.