Local when you stay local. Authenticated, scoped, and explicit when you connect.
Last updated: August 31, 2026
Without an API key, the Pathmode MCP server reads and writes intent.md on your machine. It sends no file contents, repository details, or telemetry to Pathmode.
Data you upload or sync is used to provide Pathmode. We do not train Pathmode-owned models on it; hosted model-provider processing and retention follow the service and configuration described in our Privacy Policy.
Connecting a workspace changes what Pathmode can receive
No API key
intent.md
Local MCP
Your agent
The Pathmode process makes no network request. Your coding agent may still send context to its own model provider under the settings you chose for that agent.
API key or signed-in session
App / MCP
Pathmode API
Workspace
Requests are authenticated and workspace-scoped. Hosted Google AI is called only by features that need model processing; deterministic preflight does not use it.
Comprehensive security measures to protect your data
AES-256 Encryption at Rest & TLS 1.3 in Transit
Connected workspace data is encrypted by our infrastructure providers at rest and in transit. Workspace API keys are shown once at creation, stored as hashes, and sent only as bearer credentials to Pathmode.
Authenticated Private Workspaces
Private workspace operations require an authenticated member or scoped API key. Public review links expose only the shared intent, and keyless local mode needs no Pathmode account.
XSS Protection & Secure Resource Loading
A site-wide CSP restricts scripts, frames, connections, and resource loading. It is one layer alongside server-boundary validation and output encoding, not a substitute for either.
Validation and Authorization at the Boundary
Security-sensitive and newly changed JSON, query, and path inputs are checked at the server boundary. Authentication and workspace authorization are enforced independently of validation.
Server-Side Hosted AI, No Pathmode Training
Hosted AI calls use server-side credentials. Pathmode does not train its own models on workspace content. Google provider data use and retention depend on the configured Vertex AI or Gemini service; keyless preflight sends nothing to either.
DoS Protection & Abuse Prevention
Public, AI, integration, API-key, and other abuse-sensitive routes use rate limits appropriate to the surface. Limits may be keyed by user, IP address, workspace, or credential.
Row-Level Security & Role-Based Access
Private connected data is scoped by workspace membership, roles, row-level security, and explicit authorization before privileged operations. Public review tokens are narrow, revocable exceptions.
Keyless First; Hashed and Scoped When Connected
Local tools need no key. Connected agents use workspace-scoped keys that are shown once, stored only as hashes, capped by the creator's role, optionally expiring, and revocable at any time.
Point-in-Time Recovery Enabled
Automated daily backups with point-in-time recovery capabilities for data protection and disaster recovery.
Specific controls and practices we can substantiate
Specific controls are documented in the Privacy Policy
Your data, your control
Workspaces can enable AI-assisted PII redaction for supported research and import flows. Automated detection is not guaranteed; review warnings and anonymized output before relying on it.
Primary connected data is stored through Supabase in AWS EU infrastructure. Hosted AI currently defaults to Google's global endpoint; an EU-only AI option remains unavailable until every AI entry point honors it.
Delete connected accounts or workspaces through the product; associated personal data is deleted or anonymized within 30 days, subject to legal retention. Repo-local files remain under your filesystem and version-control policies.
Export your data anytime. Contact us for a complete data export in machine-readable format.
Trusted partners who help us deliver Pathmode
We work with trusted third-party service providers to deliver Pathmode. All sub-processors are bound by strict data processing agreements. Our own DPA is available on request via security@pathmode.io.
Vertex AI with a server-side Gemini API fallback
Database and authentication services
Hosting and edge network
EU-hosted product analytics and error tracking; browser persistence disclosed in the Privacy Policy
Redis-backed rate limiting and transient service state
Transactional email and subscriber broadcasts
We take security seriously and appreciate responsible disclosure
We will acknowledge receipt within 48 hours and work with you to resolve the issue.
Structured process for handling security incidents
In the event of a security incident, we follow a structured response process:
Continuous monitoring and automated alerts help us detect incidents quickly.
Immediate steps to contain the threat and remove it from our systems.
Restore services and conduct post-incident review to prevent recurrence.
Affected users will be notified within 72 hours of confirmed incidents, per GDPR requirements.
Continuous improvement and proactive security measures
We regularly audit dependencies for known vulnerabilities and apply security patches promptly. Automated dependency scanning helps identify issues early.
Continuous monitoring of API usage, authentication attempts, and system logs helps us detect and respond to threats in real-time.
We run recurring security reviews of the codebase and ship the fixes. The June 2026 pass added SSRF protections on outbound content fetching, rate limiting across public API endpoints, and webhook replay deduplication.
Get in touch with our security team
For security-related questions, concerns, or to report a vulnerability, please contact our security team:
For security vulnerabilities and incidents
Response Time
We aim to respond to security inquiries within 48 hours