fadenstack

Security and privacy

Your AI, on your servers, under your rules.

Fadenstack runs on hardware you control. This page says what leaves your network, what is encrypted, and who can see what.

Where data goes

You decide what leaves your network.

The server, the models and the data live on machines you run. Anything that goes elsewhere goes because an admin set it up, and the console shows it.

Your server

The Fadenstack server runs on a Linux machine you operate. Chats, documents, skills, settings and logs are stored there.

Your models

Models run on your GPU machines. An outside provider is used only after an admin adds one, and every request it serves is counted.

Where it was computed

Each request is counted as served on your machines, on your private network or by an outside provider, or as unknown. The dashboard shows the share kept in-house.

Downloads

When you pick a model, the server downloads it from Hugging Face. GPU machines without internet access get the runtime and the models from your server, and the agent once its builds are on the server.

Personal data

Redact personal data before a model sees it.

The privacy module finds email addresses, phone numbers, IBANs and card numbers, and names and places in English text. Your privacy policy says what happens to them, for outside providers or for every model.

  • Redact: the model sees <PERSON> instead of the name
  • Tokenise: the model sees [PERSON_1], and the answer gets the real name back
  • It checks the message, the history, results from your documents and what tools return
  • Each MCP server is set to allow, redact or block personal data
  • The privacy dashboard shows counts only, never what it found
The privacy dashboard: how many requests were scanned, how many contained personal data, and which kinds, as counts only.
The privacy dashboard, counts only

Encryption

Encrypted on the wire and at rest.

HTTPS by default

faden deploy switches on HTTPS, with the install's own certificate authority or your certificate. TLS 1.2 and 1.3 only.

One way in

Only the web front end listens on the network. The databases listen on the server itself.

Mutual TLS to your machines

The server and your GPU machines prove themselves to each other with certificates. Ray's traffic inside a cluster can be encrypted too, with one switch per cluster.

Signed commands

Commands to machines are signed, and they travel over a connection the machine opens to the server.

Encrypted at rest

Chats and their titles, MCP credentials, the Hugging Face token, secret settings and the keys of the machines' certificate authority are stored encrypted.

Open to inspection

The server is open source under Apache-2.0. Your security team can read every line of it.

Access and audit

Who can do what, and a record of what happened.

Roles

Admin, operator, user and viewer are built in, and you can build your own from fine-grained permissions. In this release only superusers open the console; the roles apply to the API.

An audit record per request

Every request leaves a record, including the version of the skill that shaped it.

Rules with a decision log

When a rule refuses something, the decision log records the decision without keeping the refused text.

Tools under control

Tool modes and rules decide which tools may run; in the Ask mode, a tool that changes something waits for a person's approval.

Usage and cost

Per user in the dashboard, with a record of each request.

One organization per installation

An installation has one set of users, models and machines. Separate organizations run separate installations.

Single sign-on is planned for the Enterprise edition. See the editions.

The agents

What the agents keep, and where.

The browser agent

  • Conversations stay in the browser
  • It asks before it writes or clicks, once or for the whole chat, and never fills in password or card-number fields
  • You allow it site by site

The Office agents

  • Chats are stored encrypted on the computer, and the sign-in is protected by Windows
  • Edits in Word arrive as tracked changes, and most of what the agent does can be undone
  • The Outlook agent drafts mail and never sends it
On the server

For usage and audit, the server records which tools ran and how long they took. For an agent with a tool list, a tool that arrives with an app update waits for an admin.

Report a vulnerability

Found a security problem?

Please tell us privately first, through our contact form with the subject “Fadenstack security”. Describe what you found and how to reproduce it. We confirm that we received it and keep you informed while we fix it.

Please don't

Open a public issue for a vulnerability, test against installations you do not own, or access data that isn't yours.

See it for yourself.

Install it on your own server, or read the code first.