Project information

Architecture and disclosure

Security starts with accurate boundaries.

El-cro is an early product. This page documents the current trust model without claiming third-party certification.

01No certification claim
02Provider-aware threat model
03Coordinated disclosure
01

Client and extensions

The desktop app can read and modify workspace files, run terminal commands, load extensions, and connect to configured services. Treat those capabilities as privileged.

02

Agent safety

Review tool approvals, diffs, terminal commands, MCP servers, model endpoints, and generated code. Use version control and backups.

03

Report a vulnerability

Email the El-cro security contact to coordinate a private report. Avoid publishing sensitive exploit details publicly before a fix ships.

AI coding, under your control

Build with your tools, models, and rules.

El-cro puts you in control of your models, keys, and data.