Figaro · Security

Security

Individual Entrepreneur MYTHOS Development · identification number 105743713 · last updated September 2026

This page explains how Figaro protects your data and what our security model looks like in practice.

1. Consent-gate model

Figaro operates on a consent-gate principle: nothing is sent, booked, posted, or paid without your explicit approval. Every action that touches the outside world (email send, calendar booking, social post, payment) requires either a pre-set rule you authored, or a real-time tap of approval from you.

You can inspect, modify, or revoke any pending action before it executes. The default posture is draft-and-wait, not fire-and-forget.

2. Your own Anthropic API key

Figaro Home uses an Anthropic Console API key that you create and fund. It is separate from a Claude consumer subscription, and Anthropic bills API usage directly to you.

During box setup, the key is stored in your tenant-bound encrypted vault so the one-shot claim can deliver it to the hardware-bound unit. The key is not built into the factory image, published appliance, or Docker command line.

Model requests are sent to Anthropic. The box also contacts Figaro's hosted Conductor for entitlement checks and signed connector packages, so the service does not claim that all processing remains on the device.

3. Credentials encrypted at rest

Credentials entered during onboarding are encrypted at rest in a tenant-bound vault. Provisioning delivers only that tenant's required secrets into a root-owned, permission-restricted volume on the claimed box. Shared platform, release-signing, and registry credentials are not shipped to customer hardware.

The computer owner has administrative access to their unit and can read locally stored credentials. Revoke a key with its provider and contact us if the box is lost, returned, or transferred.

4. Data access and service providers

Figaro limits operational access to the systems and data needed to run, secure, and support the service. Access to production systems is restricted and audited. Support access to a customer box requires the owner's consent.

Messages, connected-account data, and task context may be processed by the model and integration providers needed for the action you request. Retention and deletion controls are described in the applicable privacy notice and provider terms.

5. Box security and code boundary

The shipped appliance verifies signed releases and uses a hardware-bound service session. Hosted Conductor source, tenant registry, playbooks, entitlement records, and private signing keys are not included in the customer image.

This provides ordinary clone resistance, not tamper-proof DRM. The box owner has root access and can inspect or modify shipped client code. Stronger protection against a determined physical attacker would require supported non-exportable hardware keys, measured boot, and remote attestation.

6. Responsible disclosure

If you discover a security vulnerability in Figaro, please report it to [email protected]. We aim to acknowledge reports within 48 hours and to resolve confirmed issues within 30 days.

Please do not publicly disclose vulnerabilities before we have had a chance to address them. We appreciate responsible disclosure and will credit researchers who report valid issues.


© 2026 Individual Entrepreneur MYTHOS Development · identification number 105743713 · Erosi Manjgaladze street N 75a, Nadzaladevi district, Tbilisi, Georgia. Questions? [email protected]