Local state and remote requests
The self-hosted core stores configuration, sessions and memory under its Flowly home directory. A remote model provider receives the request context needed for inference. Connected tools can exchange data with their own services. Local-first does not mean offline.
Command approvals are configurable
The core documentation describes security=full and ask=off as the default execution policy. That setting does not ask before each command. Configure allowlist mode or ask=always when you need tighter control. Review the sandbox and approvals reference for the exact behavior of your version.
Cloud connections and MCP
Optional cloud connectivity introduces an account and relay into the data path. Transport encryption is different from end-to-end encryption. The local MCP server is read-only by default; enabling write tools expands its scope. Connect only clients you trust with the data exposed by those tools.
Review before organizational use
Match data retention, provider terms, identity, audit and support requirements to the actual deployment. This page does not assert a certification, a universal SSO capability or a default SLA. Contact the team to review requirements and report a security concern without including secrets or private conversations.