Security
Local-first operation with explicit boundaries for backup, support, and external services.
CMT is designed to make high-impact actions visible and recoverable, while avoiding unnecessary disclosure in support material.
Local data boundary
Conversation indexing and organization operate on the selected local Codex data folder.
- Review the selected path before scanning
- Do not expose private project paths in public material
- Protect Windows accounts and backup locations appropriately
Protection for high-impact actions
Compression, cleanup, deletion, and restore use checks appropriate to their risk.
- Close Codex before database compression
- Create and verify backups before destructive actions
- Record outcomes and failure reasons in operation history
Support and external boundaries
Only intentionally exported diagnostics should leave the computer through support workflows.
- Preview and redact account names, paths, and serials
- Payment is handled by an external provider
- Review privacy and legal terms before submission
Backup confidentiality and retention
Recoverable copies can contain the same private information as the original conversation records.
- Protect backup folders with appropriate Windows permissions
- Delete expired copies according to the configured policy
- Do not send backup archives as routine support attachments
Package and update trust
Digital signature, version metadata, and SHA-256 verification help identify the intended Windows package.
- Download from the official site
- Stop if signature or checksum validation fails
- Keep the verified package while investigating an update issue
Organize Codex conversations, handoffs, and backups