Local-first commitment
Your files, knowledge and memory live in a workspace on your machine. What leaves your device is a snippet you can review — always your choice, per document.
How the agent loop works →Tidalock is local-first — your files stay on your machine. What leaves your device is a snippet you choose to send. Nothing more. Nothing silent.
Tidalock is certified to the standards enterprise teams check first — SOC 2 Type II, ISO 27001 and ISO 42001 — on a local-first architecture that keeps your files on your machine.
Your files, knowledge and memory live in a workspace on your machine. What leaves your device is a snippet you can review — always your choice, per document.
How the agent loop works →What we store, for how long, and your right to access or erase it — spelled out in plain language, and kept current as data-protection rules evolve around the world.
Read the privacy explainer →Documents, chats, knowledge and memory live in a workspace on your machine — not in our cloud.
When evaluation is on, only the snippet being scored is sent — never the whole file.
Off by default. Turn it on per document, choose the provider — or keep everything local.
The app and its local workspace are deleted together. No shadow copy on our side to clean up later.
The only path data travels. Nothing else leaves your device — no files, no full datasets, no background uploads.
The controls that come with the product — and the practices behind them.
Public documents, right away. Restricted reports under NDA — once they exist.
Restricted items appear here only after they exist — no pre-announcements.
Routine reviews, dependency checks and privacy updates — published here as they happen.
Data-flow review — local-first boundary checked across the agent loop; snippet-only egress confirmed.
Release security checklist — pre-release review steps formalized for the desktop app: dependencies, signing and permissions.
Dependency & supply-chain check — desktop runtime and libraries refreshed to supported versions.
Privacy update — retention and erasure flows reviewed ahead of public launch; privacy explainer expanded.
Privacy review — data-minimization pass across signup, billing and support flows; explainer updated.
Access review — key masking and revocation paths exercised end-to-end.
Access management — least-privilege review across internal tooling; dormant access removed.
Security baseline — threat model and incident-response playbook documented.
Plain answers, real documents, and the same honesty you just read. Ask our AI — or reach a human.
See our privacy explainer →