Data and privacy
Kraft has no telemetry. It sends no usage data, crash reports or analytics anywhere. The outbound calls it makes are listed below, and each one serves a feature you can see.
Model providers
Kraft never calls a model API itself. It runs the agent CLI you installed, such as Claude Code, and that CLI sends your code, prompts and tool output to its provider under your account and that provider's terms. What the provider keeps and for how long is set by your account with it, not by Kraft.
Under a sandbox with a
network: policy, the agent's traffic leaves through Kraft's own egress
proxy, and only to the hosts the policy and the harness allow.
Outbound calls
| Call | Goes to | When | Turn it off |
|---|---|---|---|
| Agent CLI | Its provider, such as api.anthropic.com | Every agent task | Not applicable: this is the work. |
| Update check | api.github.com, this project's releases list | kraft admin start and kraft admin doctor, at most once a day (cached in run/update-check.json) | KRAFT_NO_UPDATE_CHECK=1 |
kraft admin update | The release's wheel on GitHub, then uv tool install (PyPI for dependencies) or brew upgrade | Only when you run it | Don't run it. |
Forge CLI (gh, glab) | Your forge | Merge-request nodes: open, read checks and reviews, mark ready, merge | A chain without merge-request nodes makes none. |
git fetch, git push | Your repo's origin | Fetching the base branch, and pushing the item's branch | Not applicable. |
| Notifications | The webhook URL in notify.yaml | The events you chose, only while notifications are on | Off by default. |
| Embedding model | Hugging Face, Qdrant/bge-small-en-v1.5-onnx-Q, about 130 MB | The first vector index or search, only with the vector extra installed | Don't install the vector extra. |
The forge CLI and git calls use your own logins for those tools. The
embedding model is cached in ~/.cache/kraft/fastembed, or in
$KRAFT_EMBED_CACHE if you set it.
Secrets and state
Everything lives under $KRAFT_HOME (default ~/.kraft). Kraft writes its
config files through a temporary file created with mode 0600, so a file
Kraft has written is readable only by you. A file you created or edited by
hand keeps its own mode.
| What | Where | Mode |
|---|---|---|
| Settings password (scrypt hash) and bind | templates/access.yaml | 0600 once Kraft writes it |
| Bearer token for the CLI and MCP | run/mcp-token | 0600; kraft admin doctor checks it |
Bearer token for POST /api/triggers only | run/trigger-token | 0600; kraft admin doctor checks it |
| Notification webhook URL | templates/notify.yaml | 0600 once Kraft writes it |
Repo env: values | templates/repos.yaml | 0600 once Kraft writes it (kraft repo connect or a Settings save) |
| Everything below | run/ | 0700; Kraft sets it on every start |
| Login sessions (token hashes), work items, events | run/orchestrator.db | 0600 when Kraft creates it |
| Search index of specs, plans and other documents | run/index.db | 0600 when Kraft creates it |
| Agent logs | run/logs/ | 0600 for a session log; server.log has your default file mode |
| Agent results | run/results/ | Your default file mode |
| Attachment copies and worktrees | run/attachments/, run/worktrees/ | Your default file mode |
Agent logs hold whole sessions: prompts, the code the agent read and wrote,
and command output. Because run/ is 0700, other users on the machine cannot
reach anything inside it, whatever mode a file has. A database created by an
older Kraft keeps its mode. Treat run/ like the repositories it works on.
A repo's env: values go into each worker's process environment, not onto
its command line. Your own user and root can read them there, for example
with ps eww on macOS or from /proc/<pid>/environ on Linux. Every agent
running for that repo can read them too.
Related
- Security: the default posture and the threat model.
- The bearer token: what it grants and how to rotate it.