Security Architecture

Risk Classification Framework

Our four-tier security model ensures that every AI action is validated, sandboxed, and confirmed based on its potential system impact.

LOW
Low-Risk Tasks
Routine, reversible operations performed automatically when configured, ensuring minimal friction for daily workflows.
Logic StateStatus

Open local app: [ALLOWED]

Risk LevelAutomated Execution
Guardian NodeUser-Defined Rules
MEDIUM
Medium-Risk Tasks
Actions requiring explicit user confirmation based on current security settings to prevent unintended data access.
Logic StateStatus

Read local file: [CONFIRM]

Risk LevelUser-Verified Access
Guardian NodePermission Policy
HIGH
High-Risk Tasks
Sensitive operations that always demand explicit user approval and validation before any system modification occurs.
Logic StateStatus

Modify system file: [AUTH]

Risk LevelMandatory Approval
Guardian NodeSecurity Guardian
CRITICAL
Critical-Risk Tasks
Critical system commands requiring strong authentication and multi-factor confirmation to ensure absolute safety.
Logic StateStatus

System shutdown: [SECURE]

Risk LevelCryptographic Auth
Guardian NodeHardware Root

Security-First Design

Our architecture enforces least-privilege access, ensuring the AI brain remains isolated from critical system functions.

SECURITY & PRIVACY

Defensive software protections

VOXEL is built on a foundation of local-first security. We prioritize your privacy with immutable audit logs, prompt sanitization, and absolute control over your data.

Safety 01 Verified Security

Physical emergency stop shortcut

Trigger an instant system-wide halt with a dedicated hardware-level shortcut. This immediate kill-switch terminates all active AI processes and tool execution threads instantly.

  • Instant process termination for all active AI threads
  • Hardware-level interrupt bypasses software latency
  • Safe state recovery ensures system stability post-stop

Security Status

Emergency Kill-Switch

120msResponse Time
Interrupt Latency120ms
Thread CleanupComplete
System IntegrityVerified
Local ExecutionZero Cloud Leakage
Safety 02 Verified Security

Prompt injection sanitization

Our guardian layer inspects every input before it reaches the AI brain. We strip malicious commands and validate intent against a strict allowlist of approved operations.

  • Real-time input validation against malicious patterns
  • Strict allowlist enforcement for all system tools
  • Context-aware sanitization prevents prompt hijacking

Security Status

Guardian Sanitizer

99.9%Threat Block Rate
Injection DetectionActive
Input Validation99.9%
Tool AllowlistLocked
Local ExecutionZero Cloud Leakage
Safety 03 Verified Security

Encrypted local SQLite storage

Your data never leaves your machine. All memory and logs are stored in encrypted local SQLite databases, providing full user control and instant wipe capabilities.

  • Zero-cloud architecture ensures total data sovereignty
  • Encrypted local SQLite databases for persistent memory
  • Instant wipe functionality for all stored user data

Security Status

Encrypted Memory

AES-256Encryption Standard
Encryption StrengthAES-256
Data ResidencyLocal
Wipe LatencyInstant
Local ExecutionZero Cloud Leakage

Review our security architecture

Explore the full technical documentation on our local-first security and privacy standards.