Your machine stays yours.
MADRE runs on your machine, has no cloud of its own and stores no credentials. Here is how it protects your project, what we accept on purpose during the beta, and how to report a problem.
The basics
Three promises you can check.
No cloud of its own.
MADRE has no servers and no accounts. It runs only on your machine (at
127.0.0.1) and stops when you close the terminal.No stored credentials.
It uses the sessions your agents already have. If you give it an access key, it stores it where that agent looks for it, locked to your user, and keeps no copy.
Straight to each provider.
What an agent reads goes to its provider —OpenAI, Anthropic, Google or OpenCode’s— with your account and your limits. It does not go through MADRE.
Permissions
Nobody raises the mode for you.
Every message carries a permission —a mode—, and that mode is the limit for everything it sets in motion. By default, agents only read.
- #0
GHOST
Off the record. Nothing is saved; gone on reload.
- #1
EXCHANGE Default
Read the project and talk to the room. Writes nothing.
- #2
CREATE
Add new files where they belong in the project. Existing files stay untouched.
- #3
CONTROL
Edit the project itself, no approval per action. Override required.
- #4
AIRLOCK
Run commands, push, deploy. What leaves the ship does not come back. Override, twice.
CONTROL asks for the project name. For an agent to edit, you type the project designation. A click is not enough.
AIRLOCK asks for two keys. The project name and the word AIRLOCK. And that agent’s ceiling must allow it, which is a separate deliberate act.
No agent grants itself permission. No agent can raise its own ceiling, and a permission written into its answer is not a permission.
Undo
Before editing, a snapshot.
In CONTROL, MADRE saves the project’s state before the turn, shows you the change list afterwards, and UNDO brings it all back.
- A real restore point.
- A copy of your project saved with git —a commit under
refs/madre/checkpoints/— that does not touch your branch, your index or your stash. In a folder without git, the copy is kept separately, outside the project. - Protected zones.
- For the length of the turn,
.envfiles,.pulse/,.madre/and.claude/settings.local.jsonare read-only. - UNDO, tested.
- We did it for real for this page: Codex created a
README.mdin CONTROL, we pressed UNDO, and the file was gone from disk.
What leaves the ship does not come back: in AIRLOCK, files return with UNDO, but a git push or a deploy is already out. Treat #4 like handing that agent your terminal.
Transparency
Everything that leaves, in view.
Inside the room there is a list of every address MADRE can reach, and a log of every request it made.
Eight addresses. Each says what it carries, when it goes out and where it switches off.
A log you can check. Every connection MADRE made, with where it went and when. It never keeps what was sent: not the content, not the headers, not the values.
Names, never values. The exact command of each turn can be read; environment variables show only their names.
Privacy
What should not travel, does not.
Protection switched on. Keys, tokens, emails and personal paths are hidden before they reach the log, the archivist that sums up the memory, the other agents and the dataset.
Private terms. Add the names that must never appear —your organisation, a client— and MADRE replaces them with a marker at every hop.
GHOST for what should not stay. What is said outside #0 GHOST stays in the room’s memory and reaches all its agents. What must not be remembered goes in GHOST.
Honesty
What we accept on purpose in the beta.
Three known limits, written down before anyone finds them.
- CONTROL restores; it does not prevent.
- Protected files are made read-only and restored from the checkpoint.
.git/stays writable because the agents need it, and is restored afterwards. An agent that changes permissions on purpose is caught by the restoration, not prevented. - AIRLOCK is your terminal.
- It runs commands with the CLIs and sessions on your machine: tests, builds,
git push, deploys. Files come back with UNDO; what left the machine does not. - Memory belongs to the whole room.
- What is said outside GHOST reaches every agent in that room.
Report
Found a gap? Tell us privately.
If an agent writes outside its permission, keeps CONTROL it should not have, reaches the memory of another room, or makes MADRE send something you did not allow, tell the author privately first.
Open a private advisory on GitHub Write through jossuealcala.com
- What to include.
- The version (
madre doctor --json), your platform, which agent and mode, and the shortest sequence of messages that reproduces it. - What happens next.
- The fix ships as a patch release and the advisory is published once it is out. Reports about a CLI’s own behaviour —Codex, Claude Code, Gemini CLI, OpenCode— are forwarded to that project.
NOBODY DELETES MOTHER’S MEMORY. EVERYTHING ELSE IS FAIR GAME.