Trust

Security at Munrel.

Local-first by design. Your voice, your notes, your context — encrypted on your machine, and never sent anywhere unless you explicitly opt in.

Last updated: 2026-05-03

1. Local-first storage

Every Munrel app — Echo, Brain, Flow — stores your data in an encrypted SQLite database on your own machine. Transcripts, memory entries, generated documents, and workflow history live under ~/Library/Application Support/Munrel (macOS) or the equivalent on Windows. Nothing is uploaded by default.

Uninstalling the app, wiping the directory, or pulling the disk all behave the way you'd expect: the data goes with you, and it goes when you delete it.

2. Encryption at rest

The local SQLite store is encrypted with AES-256-GCM via SQLCipher. The encryption key is derived from a passphrase or the OS keychain (Keychain on macOS, Credential Manager on Windows). The key never leaves your device.

For users who opt into cloud sync, we use split-key encryption: half of the key is held client-side (under your control), half is held server-side. Neither side can decrypt your data alone. The Munrel operator cannot read your synced content.

3. Voice processing

Echo transcribes audio using on-device speech-to-text models (Whisper variants and successors). Your voice never leaves your machine for transcription. Audio buffers are held in memory only for the duration of the session and discarded after transcription completes.

Workflow steps that call cloud LLMs (OpenAI, Anthropic, DeepSeek, etc.) are opt-in per step. You decide which steps run locally and which use a remote model. You can also bring your own API keys.

4. Cloud option — Swiss private cloud

If you opt into managed cloud features (sync, hosted LLM, shared workspaces), your data is processed in a Swiss-jurisdiction data center operated by Munrel's parent entity in Yverdon-les-Bains, Switzerland. Switzerland's nFADP law and the EU adequacy decision provide strong baseline protections.

All inter-service traffic uses TLS 1.3. Data is encrypted at rest with per-tenant keys. Backups are encrypted, geo-redundant within Switzerland, and retained for 30 days.

5. Authentication & access

Cloud accounts authenticate via OAuth (Google, GitHub) or email magic links. Sessions use short-lived JWTs with refresh rotation. Admin actions on your account are logged and visible in your dashboard activity feed.

Two-factor authentication is available for cloud accounts. The desktop apps themselves do not require login when used in fully local mode.

6. Compliance posture

  • GDPR (EU) — Munrel is GDPR-aligned. Data subject requests (access, export, deletion) are honored within 30 days at [email protected].
  • nFADP (Switzerland) — same posture, applied under Swiss jurisdiction.
  • HIPAA (US) — Munrel is not HIPAA-certified. The local-first architecture is HIPAA-friendly (PHI never leaves the clinician's device when used in fully local mode), but we do not provide a Business Associate Agreement today. If you need a BAA, contact us.
  • SOC 2 — not yet audited. On the roadmap once cloud usage scales.

7. Vulnerability disclosure

Found a security issue? Email [email protected]. We aim to acknowledge within 48 hours and provide a fix or mitigation timeline within 10 business days. We do not currently run a paid bug bounty, but we credit disclosers in release notes when permitted.

Please do not test against production accounts that aren't yours. A local install is the right place to probe.

8. Contact

General security questions: [email protected]
Privacy / data-subject requests: [email protected]