Default
Local first, not hosted first
Core review and cockpit workflows are described as local product behavior. Hosted accounts, SSO, and organization membership are separate product concerns.
Security and privacy
FactionOS starts on the operator machine and treats external transfer as explicit.
No hosted account is required for the core local workflow. Optional services are described as separate choices rather than silent defaults.
This site does not ask for prompts, local paths, credentials, terminal output, or source code.
Trust manifesto
FactionOS is designed around local visibility for AI-assisted development work. The default path keeps hook events, mission context, and cockpit state on the machine running the local product.
That default does not turn sensitive development data into low-risk data. Prompts, file paths, terminal output, credentials, replay state, demo payloads, and user-provided code remain sensitive and need explicit boundaries before any transfer.
Default
Core review and cockpit workflows are described as local product behavior. Hosted accounts, SSO, and organization membership are separate product concerns.
Exit
War Room, outbound adapters, provider calls, demo, and docs links are treated as optional or separate surfaces with clear user action.
Telemetry
The launch site has no analytics by default. Future analytics work must be opt-in, scrubbed, documented, and blocked from sensitive payload classes.
Limits
Security copy stays tied to the current product posture and does not stand in for certification or legal policy.
Local-first is a default operating posture, not a formal security certification or a promise that every future surface is proven.
Event lifecycle
Every lifecycle step shows its default posture and operator boundary.
Claude Code hooks, Codex CLI hooks, or compatible producers can emit structured workflow events for the local product. Compatible producers can use the generic event API shape.
Default Product hook data starts in the user's local development context.
Prompts, transcripts, command bodies, credentials, and broad local paths are blocked from public-site materials.
A local ingest path can turn events into structured mission, timeline, diagnostic, and review records for the local cockpit.
Default The baseline does not require Supabase, hosted persistence, public replay, or a cloud account.
External provider transfer remains disabled unless explicitly configured and separately allowed.
The cockpit can display missions, lanes, status, replay, settings, and diagnostics when the local runtime is active.
Default Browser preferences and replay state stay in the local product context.
Public examples are previews, not connected workspace state.
War Room collaboration is optional and separate from the local baseline. Discord, Telegram, and generic HTTPS adapters are optional outbound paths. Provider analysis, the public demo, and public docs are separate from the default local path.
Default A configured external surface is required before transfer can happen, and sensitive categories stay blocked or redacted.
Optional transfer is separate from hosted identity, production auditability, and default analytics.
Browser reset, local file deletion, Worker room cleanup, backup pruning, and archive removal are different authority boundaries.
Default Each cleanup path needs its own authority, confirmation, and verification.
Manual cleanup and scoped deletion are not presented as one proven end-to-end erasure workflow.
Local data classes
Website posture, product posture, and blocked transfers are listed per data class.
| Data class | Website posture | Product posture | Blocked transfer |
|---|---|---|---|
| PromptsMission prompts and summaries can describe sensitive work intent. | This site does not request prompts. | Prompt text stays local by default and is minimized before optional provider transfer. | Raw prompt bodies are blocked from public docs, diagnostics, logs, exports, and analytics. |
| File pathsPaths, cwd values, repo names, and transcript paths can expose local structure. | This site cannot inspect local filesystem paths. | Local product surfaces redact broad paths before broad exposure. | Full local paths are blocked from website analytics, hosted diagnostics, and public examples. |
| Terminal outputCommand output can contain secrets, paths, hostnames, or source snippets. | This site does not run commands or collect terminal output. | Terminal output is not a default hook payload category and must stay narrow when summarized. | Raw terminal scrollback is blocked from analytics, public docs, and optional federation frames. |
| Local event snapshotsTimeline, diagnostic, and mission snapshots can reveal workflow context. | Public pages do not fetch local events, open WebSockets, or personalize content. | Snapshots remain local runtime state unless a user configures an outbound surface. | Diagnostics must use compact status labels, counts, timestamps, and safe family names. |
| CredentialsTokens, API keys, auth headers, and credential-bearing URLs are high-risk payloads. | This site has no login, hosted form, auth flow, or credential collection path. | Credential-like values are redacted from local logs, diagnostics, exports, and adapter payloads. | Secrets, bearer values, account ids, and credential URLs are blocked at every external boundary. |
| Replay dataReplay state and share fragments can carry local mission history. | This site does not accept replay uploads or public replay state. | Replay state is local browser state unless the user explicitly exports or shares it. | Replay buffers are blocked from Worker catch-up, hosted diagnostics, and analytics payloads. |
| Demo payloadsThe zero-install demo is a guided preview and stays separate from local sessions. | This website links to the separate demo and does not embed a live demo payload. | Demo content stays separate from local runtime state. | Real prompts, paths, scans, exports, logs, and media drafts are not demo payload material. |
| User-provided codeCode snippets and file contents can include proprietary logic or personal data. | This site has no upload, form, CMS, or code submission path. | Codebase analysis requires local user action and optional provider transfer remains two-level opt-in. | File contents and user-provided code are blocked from analytics, public examples, and default adapters. |
Optional boundaries
Collaboration
War Room collaboration is optional and separate from the local baseline. Federation is a separate Cloudflare Worker surface for room lifecycle, presence, catch-up, and allowlisted redacted events when configured.
Controls
Not included
Notifications
Discord, Telegram, and generic HTTPS adapters are optional outbound paths. Provider-style outputs are optional exits that require explicit configuration and redaction.
Controls
Not included
Hosted
Supabase, hosted storage, push, analytics, tunnels, public replay, and remote access remain disabled-default or future review surfaces.
Controls
Not included
Demo
Zero-install product preview hosted separately from this website. It is useful for inspection but not connected to a user's local workspace.
Controls
Not included
Docs
The GitBook docs are a separate public documentation surface for setup and deeper references, not a hosted product runtime.
Controls
Not included
Redaction guardrails
Redaction
Redaction is boundary-specific, so every external, diagnostic, export, archive, adapter, and future analytics surface needs explicit minimization.
Blocked payloads
Consent
Configured keys, Worker URLs, or destination links are not treated as blanket permission to send sensitive development data.
Blocked payloads
Telemetry
Passive settings and readiness copy can explain disabled analytics and hosted-service status without enabling capture.
Blocked payloads
Analytics posture
The launch site does not ship analytics. Future analytics work needs consent, scrubbing, host controls, and tests.
No tracking script, beacon, SDK import, form handler, cookie, or localStorage write is added.
Future Umami work must stay disabled by default or explicitly controllable and self-hostable.
Recorder, heatmap, replay-style inspection, console-log capture, and raw event capture stay off.
Blocked payloads
Future conditions
Analytics does not replace hosted identity, production auditability, certification, or erasure policy.
Security FAQ
No for the core workflow. No hosted account is required for the core local workflow.
SSO, organization membership, hosted identity, public collaboration safety, and production auditability are separate product concerns.
Optional hosted or Worker surfaces must be described separately from the local default.
No. This site has no hosted form, auth flow, analytics script, runtime fetch, WebSocket, command execution, cookie, or localStorage write.
The site can link to the demo and docs, but it does not inspect a local workspace or receive product hook payloads.
External destinations are separate surfaces and use explicit external link treatment.
External transfer requires a configured optional surface, such as War Room, an outbound adapter, or provider analysis that passes the project transfer controls.
Provider analysis is two-level opt-in: credentials alone are not enough; explicit provider transfer must also be allowed.
Default local behavior must not be rewritten as default hosted upload.
War Room federation is limited to allowlisted redacted room lifecycle, presence, catch-up, and collaboration event families when a Worker URL and room flow are configured.
It must not transfer prompts, file contents, command bodies, terminal output, transcripts, exports, replay buffers, logs, local diagnostics, backups, or raw authority tokens.
Worker-issued room authority is separate from hosted account identity and erasure policy.
No. The launch site has no analytics by default.
Future Umami work must be explicitly controllable, scrubbed, documented, tested, and blocked from sensitive payload classes before runtime tracking exists.
Future analytics readiness is not active website or product tracking.
Browser reset, local file cleanup, Worker room-state deletion, backup pruning, and archive deletion are separate authority boundaries.
A broad erasure workflow would need dry-run, confirmation, execution, idempotency, partial-failure handling, redacted audit, and verification across every covered surface.
Scoped cleanup is useful, but it is not one proven end-to-end erasure workflow.
This site has no credential collection path. Product code treats bearer values, API keys, auth headers, credential-bearing URLs, and account ids as blocked or redacted data.
War Room raw authority tokens are browser-held request credentials and must not be stored in localStorage, displayed, exported, replayed, logged, or copied into diagnostics.
Credential posture is separate from hosted account, SSO, and certification work.
No. The demo and docs are separate public destinations. The demo uses guided examples, and the GitBook docs hold setup and reference material.
Opening those links does not connect this site to a local FactionOS runtime or import a local workspace session.
External links open separate destinations.
Next trust checks
Zero-install product preview hosted separately from this website. Read the public docs, or follow the product and how-it-works routes to compare local, optional, outbound, and future surfaces.
These links open separate destinations and do not connect this page to a local workspace.