Security

Local-first operation with explicit boundaries for backup, support, and external services.

CMT is designed to make high-impact actions visible and recoverable, while avoiding unnecessary disclosure in support material.

CMT Codex Toolbox

Local data boundary

Conversation indexing and organization operate on the selected local Codex data folder.

  • Review the selected path before scanning
  • Do not expose private project paths in public material
  • Protect Windows accounts and backup locations appropriately

Protection for high-impact actions

Compression, cleanup, deletion, and restore use checks appropriate to their risk.

  • Close Codex before database compression
  • Create and verify backups before destructive actions
  • Record outcomes and failure reasons in operation history

Support and external boundaries

Only intentionally exported diagnostics should leave the computer through support workflows.

  • Preview and redact account names, paths, and serials
  • Payment is handled by an external provider
  • Review privacy and legal terms before submission

Backup confidentiality and retention

Recoverable copies can contain the same private information as the original conversation records.

  • Protect backup folders with appropriate Windows permissions
  • Delete expired copies according to the configured policy
  • Do not send backup archives as routine support attachments

Package and update trust

Digital signature, version metadata, and SHA-256 verification help identify the intended Windows package.

  • Download from the official site
  • Stop if signature or checksum validation fails
  • Keep the verified package while investigating an update issue

Organize Codex conversations, handoffs, and backups