Security
Last updated 7 October 2026
Tandem runs coding agents on your machine, against your code. These are the rules it's built on, and how to tell us about a problem.
How Tandem is built
- Engine credentials stay with the engine. Each coding agent signs in by itself, in its own provider folder. Tandem never reads, copies or proxies an AI vendor's tokens.
- Secrets live in the OS keychain. Tandem's own session tokens are stored in the macOS Keychain, Windows Credential Manager or the Secret Service on Linux, never in files or settings.
- Logs are redacted. Every log line passes a redactor that removes vendor keys, JWTs, private keys and other secrets before it's written.
- File access is contained. Paths are resolved and checked against the workspace, so tricks like
.., symlinks and look-alike characters can't escape it. - Approvals are explicit. When an agent asks to run a tool, you approve or deny it. Unattended work never inherits interactive full access.
- Updates are signed. The app verifies each update's signature before installing it and refuses older versions.
- Least privilege in the app. The interface runs under a strict content security policy with only the commands it needs. Each release ships a software bill of materials for its Rust and JavaScript dependencies.
- Nothing leaves without consent. Usage statistics and crash reports are off until you turn them on.
Reporting a vulnerability
Email hello@vibezeo.com with "Security report" in the subject. Include what you found, how to reproduce it and the version affected. Please give us a chance to fix it before you disclose it publicly. We'll acknowledge your report and keep you updated.