Skip to content

Security, with clear boundaries.

An AI operator needs access to do useful work. Ghost separates signed-in account access, connected credentials, device permissions, and the tools that carry out a task.

Private beta for Mac · Product security overview

Understand the controls

Start with a signed-in account.

Ghost’s sign-in flow creates an authenticated account session. The backend checks signed access tokens, including their expiry, issuer, and intended audience, before accepting authenticated requests.

That account identity is distinct from an integration connection or a Mac permission. Signing in to Ghost does not, by itself, connect every work account or grant access to every local resource.

Protect the credentials behind a connection.

Direct integrations such as Google, Slack, and Atlassian encrypt their credential payloads with AES-GCM before storing them in the database. The stored record includes the encrypted payload and its nonce, associated with the relevant account and service.

An authorized Ghost service can decrypt those credentials to use the connection. Encryption at rest protects a stored credential; it does not mean the service can operate without ever accessing it.

Provider consent and the granted scopes determine what a connection can access. Explore Ghost integrations to understand how direct connections, your browser session, and local services differ.

Local work has local permissions.

The Mac app is the bridge to resources on your device. Microphone, screen-capture, accessibility, and other OS permissions depend on the capability you use and your system settings.

A browser task uses a connected browser session. Meeting capture uses the audio access available on your Mac. Local file work uses the files and folders made available to the relevant tool. These are separate access paths, not one blanket permission.

Use meeting capture with appropriate participant consent, and review the access involved in computer tasks before starting sensitive work.

Understand what an action can change.

Reading a page, editing a local file, and changing a signed-in account have different consequences. Ghost’s tools have their own permission and approval behavior; an existing authorization can cover some work, while another action may need confirmation.

Give the task a clear scope. Review consequential changes, check the result, and distinguish a draft from something that has been sent or published. An approval is permission for the described action, not a guarantee that its outcome will be correct.

Sandboxes provide a separate workspace for supported jobs. A remote workspace and a task on your own computer do not have the same access boundary.

Know where the work is processed.

Ghost combines a Mac app, backend services, and configured AI and integration providers. Relevant content can be sent to those services when a task needs it. Using a desktop app is not the same as an entirely local or offline workflow.

Disconnecting an account and deleting a saved record are also different operations. A connection can stop being available while a related note or meeting record remains. Review the records you want to keep and the services involved before using sensitive information.

Questions about security.

Does Ghost run entirely on my Mac?

No. The Mac app provides local access, while backend services and configured providers support agent work. A task can send relevant content to those services. Connected accounts and cloud processing are different from a fully offline workflow.

How are connected-account credentials stored?

Supported direct integrations encrypt credential payloads with AES-GCM before database storage. An authorized Ghost service can decrypt those credentials when it needs to use the connection. This is encryption at rest, not an end-to-end encryption claim.

Does every action require a separate approval?

No. Approval behavior depends on the tool, the action, and the configured permissions. Some actions can run within an existing authorization; others need an explicit approval. Review the task and its access before asking Ghost to act.

Can I disconnect an integration?

Supported integrations provide connection-status and disconnect controls. Removing a connection is different from deleting information already saved in a note, meeting, or other record. Manage those records separately when needed.

Where can I clarify security requirements before using Ghost?

Ghost is in private beta. Use Request access to discuss the workflow and its requirements, including provider processing, retention, access, or deployment details. This overview describes product controls; it is not a privacy policy or a compliance certification.

Discuss the workflow before connecting it.

If your work has specific security, retention, or provider requirements, raise them during private-beta onboarding. This overview describes product controls, not a compliance certification or privacy policy.

Request access