Local by design.
Your agents run on your computer, in real terminals, under your own accounts. Your code, prompts, and terminal output never pass through a Helmsman server. The app opens five connections on its own and six more when you ask, and this page lists all eleven.
checked · v0.15.0-beta.1 ·
Leaves your computer.
Every connection the app itself opens. The five that run without asking carry none of your code, prompts, or terminal output. The six you start carry only what their row names.
| Connection | Carries | Goes to | When | Turn it off |
|---|---|---|---|---|
| Runs without asking, 5 connections | ||||
| Sign-in | Sign-in tokens. At sign-in and once each launch, your install id, to link this copy to your account. This runs with analytics off too. | helmsman.sh | First launch, then each launch | Required. The app opens only when you are signed in. |
| Launch analytics | Four fields: the event, a random install id, the app version, the OS major version. Your account holds the same install id. | helmsman.sh | Each launch, and your first spawn | Switch. The launch analytics switch in Settings. Delete my analytics erases what was sent. |
| Update | A build key that every copy shares, and a random update id that the updater keeps on disk. No account. A new build downloads by itself and installs when you quit. | helmsman.shthen Cloudflare R2 | 5 s after launch, every hour, and on wake or focus | Switch. The automatic update switch in Settings. With it off, Helmsman checks only when you ask. |
| Settings sync | Two preferences: the caffeinate default and the usage direction. | helmsman.sh | Each launch, and when you change one | No switch. It stops only when you sign out. |
| Plan usage |
Your Claude Code access token, read from the Keychain or
~/.claude/.credentials.json. The request names itself as Claude Code.
Anthropic answers with your plan limits.
| api.anthropic.com | At launch, then every 3 minutes | Switch. The plan limits switch in Settings. It runs only while Claude Code has a Claude plan sign-in. |
| Only when you start it, 6 connections | ||||
| AI with your key | The diff for a commit message. An issue and short project excerpts for a criteria draft. A goal and your test, lint, and typecheck commands for a goal check. A dictation to polish. | api.anthropic.comapi.openai.com | When you ask for one | Remove your key. Commit messages and criteria drafts can use a local Ollama model instead. |
| Agent installers | Nothing about you. Each agent CLI's official installer, or Node through Homebrew on macOS. Both are vendor code that runs as you. | claude.airegistry.npmjs.orgHomebrew, and each vendor's own host | In First Setup or Settings, when you confirm | Do not confirm the install. |
| Hail speech model | Nothing about you. A download of the Whisper model. | huggingface.co | When you turn on Hail | Leave Hail off. |
| Account actions | A new display name, a sign-out on every machine, or a request to delete your analytics or your crash reports. | helmsman.sh | When you click one | Nothing runs without the click. |
| Crash reports | Seventeen fields after a crash: the kind, the versions, up to 30 places in the app's own files, and for a sudden quit a short summary of the macOS crash report. No message, no path on your computer, no content. | helmsman.sh | After you click Send, or after each crash if you chose Always. | Choose Never in Settings › General. |
| Skills and Apps | Nothing about you to browse. Installing an App downloads its code from the host the catalog names, and that code runs as you. | raw.api.github.comgithub.comand each App's own host | When you open the library or install | Stay out of the library. |
Your agent CLIs, gh, and git talk to their own services under your
own accounts, the same as in your terminal. Browser cells load the pages you open, and at
launch they reload the pages on screen. None of these counts among the eleven above.
Stays on your computer.
Helmsman sits between you and your terminals. It never sits between your terminals and the internet.
Terminals
Each agent runs in a real terminal on your computer. Helmsman shows its output and sends
your keystrokes. Supported agents also get the local Fleet MCP server
(--mcp-config for Claude Code, -c flags for Codex) and status
hooks that report to the app.
Your code
The grid, the diff viewer, and file search read your projects on disk. Helmsman uploads none of it on its own.
Voice
Hail turns speech into text on your Mac. The audio never leaves it. The text leaves only for the optional polish, under your own key.
Listeners
Helmsman's own listeners bind to 127.0.0.1 only: Fleet MCP while the app runs, a one-time listener at sign-in, and one while a downloaded macOS update waits to install. Each App you start runs its own server, on the address that App picks.
Locked on your computer.
Where your secrets live, what agents may do to each other, and the walls around the app.
Secrets
- Sign-in token
- Encrypted with your system's key store (the Keychain on macOS), in a file of its own. The short-lived access token stays in memory.
- AI keys
- Encrypted the same way. Remove one in Settings at any time.
- Linux, no keyring
- Helmsman refuses to save your sign-in token or an AI key. It never falls back to plain text for them.
- Agent sign-ins
- Stay with each CLI. Helmsman reads the Claude Code sign-in for the plan usage call and a yes-or-no check in First Setup. It sends the token to Anthropic only.
Agents
- Steering
- A session steers only itself and the sessions it started. No agent can turn on Skip permissions for a session it starts.
- Pre-approved subagents
- Off by default, per project. When you turn it on, an agent can start a session with edits accepted, with a list of tools that run without a prompt, or as a Codex session that never asks. A card you send from a board always starts with Helmsman's own board tools pre-approved, and no others.
- GitHub issues
- Agents can read and write issues through Fleet MCP, under your own
ghsign-in.
Walls
- The app window
- Runs sandboxed under a content security policy. Links open in your browser.
- Browser cells
- Run sandboxed and isolated, with no Node access. Every permission request is refused. They share one cookie store, kept across launches.
- Apps
- Run on your computer as you, with your files and your environment, API keys included. Only their window is sandboxed. Install only Apps you trust.
- The app binary
- On macOS and Windows, it cannot run as a plain Node process, it ignores NODE_OPTIONS and the inspect flags, and it checks its own code archive at launch.
- Updates
- On macOS, an update installs only when it carries the same Apple Developer ID (Team N3LDX57DSS) as the app you run. Windows and Linux updates are checked against a checksum from the same feed.
Check it yourself.
Do not take this page's word for it. The macOS build is signed and notarized.
Watch the analytics
Quit Helmsman first. Then start it from a terminal with this variable. It prints each analytics ping, and a delete request if you make one, and sends none of them. Every other connection in the table still runs.
HELMSMAN_TELEMETRY_DEBUG=1 /Applications/Helmsman.app/ Contents/ MacOS/ Helmsman
Check who built it
Gatekeeper answers with these three lines. Any Team ID other than N3LDX57DSS
is not our build.
spctl -a -vv /Applications/Helmsman.app
/Applications/Helmsman.app: accepted source=Notarized Developer ID origin=Developer ID Application: ... (N3LDX57DSS)
Match the checksum
Compare the hash with the one on Verify your download. The hash proves the file arrived whole. The check above proves who built it.
shasum -a 256 ~/Downloads/Helmsman-0.15.0-beta.1.dmg
Report a problem.
Email hello@helmsman.sh with
Security in the subject. Say where the problem is and what it can do, and give
the steps to reproduce it and your app version.
We reply within 3 working days. We fix a confirmed problem before we discuss it in public.
If you test in good faith under these rules, we treat your research as authorized, and we take no legal action against it. Do not access or change other people's data, do not degrade helmsman.sh for anyone else, and do not use social engineering or physical tests. The same contact is in security.txt.
On the site side, helmsman.sh keeps your account and its sign-in sessions, with the IP address and browser of each. The release-notes list keeps your email and the time you joined, for one short email per release. The privacy policy is the legal record.