HEADMASTER / SECURITY

Your work.
Your boundaries.

Useful autonomy starts with understanding what is connected, where the work runs, and which actions are allowed.

Read the privacy and security guide ↗
01

Know where the work runs.

The desktop app can connect to a hosted runtime or operate with a local runtime. Its current direction prioritizes hosted access, with local operation available as a fallback. Your deployment determines where runtime data is processed.

02

Choose what gets connected.

Model requests can include your prompt, relevant conversation context, memory and file contents. Connected tools receive the arguments needed for their actions. Check the policies and access scopes of the services you use.

03

Set permissions for the engine.

Approval behavior depends on the engine and permission mode. Some modes ask before acting; others allow actions within their configured scope. Headmaster does not guarantee that every external action pauses for review.

04

Protect each part of the setup.

Use narrowly scoped credentials, protect the runtime account and device, and revoke unused connections. Credential storage and retention differ between local and hosted configurations.

A configuration you understand.

Local operation can still call cloud models and connected services. Uninstalling the app does not automatically remove records held by those providers. Review your setup before adding sensitive data.

We do not claim independent security certification on this page.

Talk to GCAP Labs ↗