Security Policy

CLI Pulse — Last Updated: April 28, 2026

CLI Pulse touches local credentials and AI provider APIs, so security and privacy are explicit product goals. This page tells you how to report a vulnerability and summarizes how user data is handled. The full privacy policy is on privacy.html.

Reporting vulnerabilities

If you believe you've found a security or privacy issue in CLI Pulse, please report it privately first.

Please do not open a public GitHub issue for unfixed security vulnerabilities. Public issues are appropriate for general bug reports and feature requests.

We aim to:

Responsible disclosure

Data-handling summary

Detailed table: data-handling.html. Key guarantees:

Credential handling

Local helper

CLI Pulse for Mac uses a local helper component to perform on-device collection. The helper:

The helper does not phone home with raw credentials, raw cookies, or raw session-log contents. Its uploads are limited to the metric and metadata categories described in data-handling.html.

Remote sync

User controls

Out of scope

Contact