Authority model
CAMIDAX is being designed around owner authority, recognizable paired devices, role-scoped accounts and explicit approval for sensitive actions. Turning on a feature is not intended to grant unlimited background authority to every subsystem or AI model.
What local-first means
Local-first means core household device and file workflows are intended to operate primarily under the owner’s devices and permissions. It does not mean every optional integration is offline, that no network traffic occurs, or that every feature is end-to-end encrypted today.
Cloud AI and Forge
Forge is intended to support both local models and optional cloud providers. If a user chooses OpenAI, Anthropic, Google, xAI or another provider, the prompt and selected context must be sent to that provider to receive an answer. That processing is governed by the provider’s own terms, retention settings and privacy policy. CAMIDAX will surface the selected destination before transmission and should minimize context to what the user approved.
Public website boundary
The public website hosts product information and approval-only account services. It is not intended to expose private household file APIs, remote-control endpoints or local device data. Essential authentication uses a Secure, HttpOnly, SameSite=Strict session cookie.
Current security status
Security hardening, cryptographic pairing, encrypted peer transport, signed entitlements, mobile credential handling, update verification and broader release certification are active development areas. CAMIDAX is not claiming an independent security audit or production certification at this stage.
Security reporting
Use the contact form and select “Security report.” Do not include passwords, private keys, access tokens or live exploit payloads in the first message. A dedicated security address and disclosure policy will be published before general release.