Security
Real controls in the Alpha, and the boundaries they do not replace.
Last updated September 22, 2026Local-first execution
Claude Code and Codex run on your Mac under your user account. Horme starts work only in projects you add and trust.
Isolated Git worktrees
Concurrent runs can use separate Git worktrees and branches. This keeps Git state apart. A worktree is not an operating system sandbox and does not prevent a local process from accessing other files your account can read.
Credentials
Horme does not collect or store Claude Code or Codex credentials. Provider tools use their own local sign-in. Sensitive server credentials are not intended for the browser.
Human intervention
Needs You surfaces questions, approvals, meaningful stalls, and failures that require judgment. Provider limitations are shown rather than hidden.
Truthful verification
Review distinguishes checks observed to run from checks that were skipped or not verified. Agent summaries are not treated as proof by themselves.
Attachments
Attachments and pasted content are treated as untrusted input. They can contain code, secrets, or instructions, and may be passed to the coding provider that handles the related work.
What we do not claim
- No SOC 2 or ISO 27001 certification
- No claim of an independent penetration test
- No claim that the Alpha is free of vulnerabilities
Report an issue
Email hello@usehorme.com with steps to reproduce, impact, and where you found the issue. Do not access data belonging to someone else or run destructive tests. Horme does not currently offer a bug bounty or fixed response time.