Security & privacy

What runs on the server

For every feature, what Gatesys SSH runs on your servers and what it sends to a model, where the prompt goes, and how secrets are masked.

This page sets out, feature by feature, what Gatesys SSH runs on your servers and what it sends to a model, so you can decide what to switch on for which provider.

The short version

  • Nothing is installed on the server. What the app learns about a host, it reads over the SSH session you opened, on an extra channel, running commands from a fixed catalog as your own login. No agent, no daemon. It writes files on the server only when you ask it to: your uploads and saves, and during a Safe Change its staged copy (removed afterwards), its backup under /var/backups/gatesys and its safety net.
  • Nothing is read from a server just to build a prompt. The OS and shell in Farabi’s context come from the metrics sample the terminal header already shows.
  • One provider per request, one sender. Whatever is sent goes to one provider: the one a Farabi conversation picked in its panel, or else the default in Settings › Farabi › Model. Only the app’s main process sends it, and only to a provider saved in the list. The window itself keeps a strict content security policy and never reaches the network.
  • Hooks are yours to add. Nothing about your activity leaves the computer through hooks until you add one, and then only to the destination you named, redacted and, by default, masked.
  • The master switch is absolute. With Use the assistant off, nothing is sent to any model, not even a health check.

Feature by feature

FeatureRuns on the serverSent to the model
Farabi, a questionNothing. A suggested command reaches your shell only when you click Insert (typed, not run) or RunFarabi’s system prompt (the safety core, then your instructions and the conversation’s skills), your question, earlier turns (your questions and Farabi’s explanations, not its commands) and the host’s display name. With Send host context: OS, login shell, jump-chain names, the Host facts block, the Neighbours block and the last 4,000 characters of the terminal, each fenced as data
Hop Doctor’s checksNo login and no command on the host that failed. At most one bare TCP connect to its configured port to read the greeting, and a read-only getent hosts (dscacheutil on macOS) on the bastion in front, or on up to two related bastions you already have openNothing
Hop Doctor’s Explain (on click)NothingThe report, fenced: cause, headline, each hop’s checks and evidence, and each fix the rules found. Off this computer: names as placeholders, and no greeting, ident, ssh config line, key, host key or last-login time
Host factsThe fixed catalog of read-only checks, once per connect and at most every ten minutes, on a second channel of the sessionNothing of its own; the Host facts block rides along with Farabi’s questions
Service mapTwo sections of that same read: the host’s addresses and its established TCP connections, counted on the serverNothing of its own; the Neighbours block rides along with Farabi’s questions. The impact line under a command is code’s and never sent
HealthNothing extra most of the time: it reads the metrics sample. While CPU or memory is hot, or the Health panel is open, one read-only ps at most every 10 seconds, and once a minute a df of the local filesystems, on the session’s background channel. See Server healthNothing. Ask Farabi (Pro) sends a Health block: the metric’s last hour as minimum, average, maximum, 95th percentile and slope (never the points), the active signals and their evidence, the top processes, related facts and changes, fenced as data. Off this computer: no addresses, and other hosts as placeholders
Explain changes (on open)NothingThe numbered list of what changed (at most 30 lines, each scrubbed), fenced, and your one-line symptom
A watchNothing, ever. It reads output and metrics the app already receives, and never writes to the shell, runs a command or opens a channelUsually nothing. Only for a sentence the rules cannot fully read: the watch reader’s prompt, whether the pane has a terminal and live metrics, three worked examples, and your sentence with secrets masked and its quotes, hosts, addresses, paths, logins and ports as placeholders, on every runtime
A tunnel or host draftNothing while it is a draft. On Create & start: the forward, and one test connection through itUsually nothing. Only for a sentence the rules cannot fully read: the setup reader’s prompt, three worked examples, and your sentence with secrets removed and every host, address, login, path, number and quote as a placeholder, on every runtime
Safe Change review (sheet open)From a fixed catalog: one read-only preflight as your login, then as root or with sudo -n the server’s check on a staged copy (uploaded to ~/.gatesys/upload, staged under /var/lib/gatesys/stage, both removed afterwards) and sshd -T -C for this login before and after. On a production host that declined host facts, only after a click that shows the commandsWith the assistant on and Review config changes: the diff’s hunks (at most 3 KB), redacted line by line and fenced, and the app’s own check results. Off this computer only after you allow that provider once, and with placeholders
Safe Change apply (on click)The fixed install script as root or with sudo -n: stage, check, back up, arm the safety net, install, recheck, reload. Keep and revert are fixed scripts tooNothing. A Farabi draft (on Draft) sends the file’s active lines (at most 6 KB), redacted, with the sshd keywords it may use and your sentence, under the same consent and placeholders
Test this model (on click)NothingOnly the app’s own test material, and with Test with my Farabi prompt on, your instructions and default skills. None of your hosts, terminals, facts or history

Where the prompt goes

ProviderDestination
Local: Ollama, LM Studio, llama.cppThe endpoint you set, which defaults to loopback, so nothing leaves this computer. An endpoint on another machine, or a loopback port that is a Gatesys SSH tunnel to one, counts as leaving it, and Settings says so. So does an Ollama cloud model, whose prompts your local Ollama forwards to ollama.com
Cloud: Claude, OpenAI, GeminiThe endpoint in Settings, with your key from the local vault. Picking the provider sets it to the vendor’s own API over HTTPS. If you point it at a gateway, that host receives the prompt and the key, and Settings, footers and the audit log name it
Agent CLIs: Claude Code, CodexThe CLI, started as a child process with the prompt on standard input. It sends it to Anthropic or OpenAI under your own sign-in. The CLI is made unable to act, and a tripwire stops it on its first tool call. See AI providers

When a prompt leaves this computer

A prompt counts as leaving when it goes to a cloud API, an agent CLI, a local runtime on another host, or a loopback port that is a Gatesys SSH tunnel to one. It then gets stricter treatment:

  • The Host facts block loses IP addresses, emails and logins, fingerprints, host names, registry hosts, and /etc paths, even in your own notes (and there, other saved hosts’ names).
  • Hop Doctor’s Explain replaces host names, addresses, users, key paths, your local account and home folder, remaining IPs, emails and fingerprints with placeholders, swapped back only in the text you read. It leaves out the ssh config, key file, host key, last-login and server greeting and ident evidence altogether.
  • Explain changes reduces paths under /etc and home folders to their file names (unless your symptom names the path), IP addresses to [ip], emails and logins to [email] and host names to [host]. What you did through the app, read from the audit log, loses every path but the file name, and your saved hosts’ names.
  • The Neighbours block goes with every host as a placeholder and no addresses.
  • Watches and setup drafts go with placeholders on every runtime, local ones included.

Farabi's own questions are the exception

The host’s display name, and with host context on, its jump chain’s names and the terminal output, go as they are, apart from secret masking. Only the Neighbours block is slotted. Turn Send host context off for a provider you would not show your terminal to.

Secrets are masked

Settings › Farabi › Privacy › Redact secrets before inference is on by default. It masks, in your question, the earlier turns and the terminal output:

  • Private keys, including PKCS#8’s bare BEGIN PRIVATE KEY and a key only half in view (a head that shows BEGIN and no END, or a long cat that scrolled BEGIN out of view)
  • NAME=value assignments whose name ends in a secret word, such as DB_PASSWORD, AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN
  • Authorization headers and bearer tokens
  • sk- and sk-ant- keys, and Slack, AWS, GitHub, GitLab and Google keys
  • JWTs
  • mysql -p…, sshpass -p …, curl -u user:… and wget --user
  • The word after a bare password, passphrase or pw label
  • Credentials in URLs

Masking runs after invisible characters are stripped, so a zero-width space slipped into DB_PASSWORD does not hide the value.

These are masked whatever the switch says: the Host facts block, both Explains, a watch or setup sentence sent to a model, and the audit log’s copy of an inserted or run command.

The master switch

Settings › Farabi › Use the assistant off hides Farabi, both Explains, Ask Farabi, the starter prompts, the palette entry and Test this model. It stops a model test and every model call in flight, and the main process refuses every model call, including the provider health check.

What needs no model keeps working: Hop Doctor’s checks, host facts, the brief and its chips, Look closer, Health’s signals, the command-risk rules, the Connections card, the terminal’s link and escape rules, watches and setup drafts read by rules (their footer says The assistant is off — read by rules), and Safe Change without its Farabi parts.

On the record

The audit log keeps what a model’s output led to, not every call:

  • An inserted or run command, with the runtime and model that suggested it, and its impact line
  • A watch started from a model’s reading, with who read it and where
  • Hidden lines removed before a question
  • An agent CLI stopped by its tripwire
  • One line per model test

Questions to Farabi and the two Explains are not logged one by one.

Something unclear or wrong? Tell us.