Robin

Security

How Robin handles your material, and how to report a problem.

This page reflects the project's real security policy. Certification and infrastructure claims are marked as placeholders and must not be published unverified.

The shape of the system

On the local-first path, indexing, storage and the interface all run on your own machine, so meeting content never leaves it except when a question is sent to your chosen model provider. On the hosted path, accounts are isolated from one another.

Credentials

API keys and connected-account tokens are stored for your account only, and are never shown back to other users or embedded in generated output. Connecting a drive or mail account is a separate, explicit step from signing in.

What Robin will not do

Reporting a vulnerability

Please do not open a public issue. Report it privately through a GitHub Security Advisory on the repository, or contact the maintainer directly.

Include a description of the issue and its impact, steps to reproduce if you have them, and any relevant logs with API keys and personal data redacted.

Scope we care most about

Response

Expect an initial response within a few days. Fixes ship as soon as they are verified. There is no fixed disclosure timeline at the project's current size.

Compliance

Placeholder. Do not claim SOC 2, ISO 27001, HIPAA or GDPR certification here until it is actually held, and dated.