Security model
OpenFoxy combines local-first AI with server-operated account, update, coordination, sharing, advertising, billing, support, and optional Cloud services.
Signed software and updates
Production OpenFoxy releases are intended to use platform-appropriate trusted signing and secure update verification. Security, privacy, compatibility, protocol, or measurement-critical releases may be mandatory.
Account security
New accounts require email verification. Password-reset links are time-limited. Sensitive account actions may revoke sessions or require reauthentication.
Local Node security
Supported local Nodes use authenticated registration and outbound coordination. Device tokens and sensitive credentials should not be exposed in logs, screenshots, public repositories, or support messages.
Privacy boundaries
Local inference is designed to keep supported model execution on the user's machine. Connected features may still transmit the minimum information necessary to provide those features. We therefore describe OpenFoxy as private by design, not “100% private.”
Reporting vulnerabilities
Security concerns may be reported to support@openfoxy.com. Do not include passwords, private keys, payment-card numbers, or other authentication secrets.
Good-faith research
We encourage responsible, good-faith vulnerability reporting. Do not access other users' data, degrade service, perform destructive testing, or publicly disclose an unresolved vulnerability before allowing reasonable time for remediation.
These documents are product-policy drafts and should be reviewed by qualified counsel before large-scale commercial launch.