# Security & permissions

import { Callout } from "nextra/components";

Pane runs on your machine. Your code never leaves your machine because of Pane. It only leaves when the agents you run (Claude Code, Codex, Aider, etc.) send context to their providers. Pane is a terminal host, not a proxy.

## What Pane does NOT do

- Does NOT sandbox the agent process. The agent runs with your full shell permissions.
- Does NOT proxy AI API requests. Requests go directly from the agent to the provider.
- Does NOT see agent prompts, completions, or file contents the agent reads or writes.
- Does NOT run a cloud service. Remote Pane connects to a daemon you install on your own machine.

## Local-first by default

There's no Pane backend and no cloud sync. Your repos and worktrees live exactly where you put them on disk. Opening a pane doesn't upload your code anywhere. Pane's own network calls are an update check to GitHub, model prices from OpenRouter for cost estimates, and the product analytics described below.

Remote Pane is opt-in. When you connect to a VM, WSL box, or another machine, everything runs on that remote host through your self-hosted daemon. The desktop app or browser app at [runpane.com/app](https://runpane.com/app/) connects with a `pane-remote://...` code from `Settings > Remote Access > Remote Pane`. Your code stays on that host. Pane still doesn't touch API requests.

Remote Pane is free and open source. There's no hosted backend or subscription. You provide the machine and any provider credentials your agents need.

## Open source, AGPL-3.0

Pane's source is at [github.com/greenfield-inc/Pane](https://github.com/greenfield-inc/Pane). You can audit it, fork it, or build on it. AGPL-3.0 means network-served derivatives stay open source under the same license.

## Telemetry

Product analytics are on by default. Pane uses [PostHog](https://posthog.com/privacy) to record which features you use (pane creation, agent launch, keyboard shortcuts) and your OS and app version. If it finds them on your machine, Pane ties those events to your GitHub username, or your git email or name, from `gh` or your global git config. So these analytics aren't anonymous.

The website (runpane.com) also records page views with PostHog.

Here's what's **never** sent:

- File contents or code from your repos
- Agent prompts or responses
- API keys or secrets
- File paths beyond worktree names

To opt out: **Settings > Privacy**, then turn off **Allow product analytics**.

## Agent permissions

Each agent has its own permission model: Claude Code uses `.claude/settings.json`, Codex has its own approval prompts, Aider has confirmation flags, and so on.

Pane's built-in buttons start agents in their skip-the-prompts modes, so they can work without stopping to ask:

| Agent | Pane starts it as |
|-------|-------------------|
| Claude Code | `claude --dangerously-skip-permissions` |
| Codex | `codex --yolo` |
| Cursor | `cursor-agent --force --trust` |

The worktree keeps an agent's changes away from your main branch, but the agent can still run any command your user can. Want an agent to ask first? Add it as a [custom command](/docs/custom-agents) with your own flags, like plain `claude`.

## Worktree isolation

Agents in one pane can't read another pane's worktree files unless you explicitly pass a cross-worktree path. Different working directories means different file-scope defaults for each agent. This is a soft boundary based on working-directory conventions, not a kernel-level sandbox.

## Remote daemon security

<Callout type="warning">
Treat connection codes and bearer tokens like SSH private keys. Never paste them in public channels.
</Callout>

Remote Pane authenticates every connection with a <Term id="bearer-token">bearer token</Term> embedded in the `pane-remote://...` code. The token is generated on the host during setup and gives full session control to whoever holds it.

**Encryption**: <Term id="tailscale">Tailscale</Term> wraps the connection in WireGuard encryption. No ports are opened on the host. When Tailscale isn't available, the <Term id="ssh">SSH</Term> tunnel fallback provides AES-256 encryption with the daemon bound to <Term id="loopback">loopback</Term> only.

**Rotating tokens**: Run `pane --remote-setup` on the host to rotate. Revoking a client in Settings > Remote Access > Remote Pane invalidates that client's token immediately.

**Connected devices**: The host shows every connected client by device label. You can disconnect or revoke any client from Settings > Remote Access > Remote Pane.

**Data isolation**: Each data mode (Current Pane Data vs Isolated Daemon Data) uses separate databases and worktree directories. Sessions don't cross mode boundaries.

For remote browser voice dictation, the daemon host uses voice provider keys from `Settings > Integrations > Voice transcription` or host environment variables. Live streaming uses Deepgram plus OpenRouter. Batch recorded transcription uses Fal plus OpenRouter.

## Reporting a vulnerability

Email **hi@runpane.com** with subject line `[SECURITY]`. We'll acknowledge within 48 hours and reach a disclosure decision within 14 days.
