Skip to content

Security

Last updated 7 October 2026

Tandem runs coding agents on your machine, against your code. These are the rules it's built on, and how to tell us about a problem.

How Tandem is built

  • Engine credentials stay with the engine. Each coding agent signs in by itself, in its own provider folder. Tandem never reads, copies or proxies an AI vendor's tokens.
  • Secrets live in the OS keychain. Tandem's own session tokens are stored in the macOS Keychain, Windows Credential Manager or the Secret Service on Linux, never in files or settings.
  • Logs are redacted. Every log line passes a redactor that removes vendor keys, JWTs, private keys and other secrets before it's written.
  • File access is contained. Paths are resolved and checked against the workspace, so tricks like .., symlinks and look-alike characters can't escape it.
  • Approvals are explicit. When an agent asks to run a tool, you approve or deny it. Unattended work never inherits interactive full access.
  • Updates are signed. The app verifies each update's signature before installing it and refuses older versions.
  • Least privilege in the app. The interface runs under a strict content security policy with only the commands it needs. Each release ships a software bill of materials for its Rust and JavaScript dependencies.
  • Nothing leaves without consent. Usage statistics and crash reports are off until you turn them on.

Reporting a vulnerability

Email hello@vibezeo.com with "Security report" in the subject. Include what you found, how to reproduce it and the version affected. Please give us a chance to fix it before you disclose it publicly. We'll acknowledge your report and keep you updated.