⚠

E2E Encryption is on the roadmap and not yet implemented. All connections are encrypted in transit (TLS/WSS), but the relay can theoretically read messages passing through it.

Security & Privacy

We built 49Agents as a relay, not a vault. Your terminal data and file contents pass through — they are never stored on our servers.

Architecture

Every connection uses WebSocket Secure (WSS) with TLS encryption. The cloud server is a stateless relay — it routes messages but never inspects or stores them.

Your machine
wss://
Cloud relay
wss://
Your browser

The relay never decrypts, parses, or logs the content of messages flowing between your agent and your browser.

What goes where

Here's exactly what data lives where. No surprises.

Terminal output Streamed in real time, never written to disk on the server relay only
File contents Read on your machine, passed through to browser on demand relay only
Git data Branches, diffs, and commit history — relayed, not stored relay only
System metrics CPU, memory, disk — relayed to your browser in real time relay only
User profile Display name, email, avatar URL (via GitHub or Google OAuth) stored
Agent metadata Hostname, OS, last connected timestamp stored
Auth tokens Signed JWTs (HMAC-SHA256), stored locally at ~/.49agents/ with 0600 permissions local
Pane layout Your canvas arrangement, synced for multi-device access stored

At a glance

What we never touch vs. the small amount of metadata we store.

✓ Never stored
Terminal input & output
File contents
AI conversations
Source code & git diffs
Passwords (OAuth only)
API keys & secrets
○ Stored (metadata)
Canvas layout positions
Note content & images
User preferences
Agent hostname & OS
OAuth profile (email, name)
Signed JWT tokens
Usage analytics & events

Encryption & transport

Everything in transit is encrypted. Everything at rest is hashed or stored server-side with restricted access.

Security

We designed the system so you don't have to trust us with your code.

Stateless relay

Terminal output and file contents pass through the relay and are immediately forwarded — never buffered, logged, or written to disk. If the relay restarts, there is nothing to leak.

No passwords

You authenticate with GitHub or Google OAuth — no passwords to manage. Guest sessions are available for trying the product before signing up. Browser sessions use short-lived JWT tokens (1 hour) with automatic refresh.

Your machine, your control

The agent runs as your local user with no elevated privileges. Auth tokens stored at ~/.49agents/ with restricted file permissions (0600). Uninstall anytime.

Token security

Agent tokens are signed JWTs stored only on your machine with restricted file permissions (0600). Browser sessions use short-lived access tokens (1 hour) with longer refresh tokens (7 days). Pairing codes expire in 10 minutes.

Isolation

Browsers never see agent tokens. Agents don't know about browser sessions. The relay routes by user ID — one user's traffic can never reach another user's agents or browser.

What runs on your machine

A lightweight Node.js process that manages your terminal sessions and relays them to the cloud. Minimal footprint.

Dependencies (just 2)

ws
WebSocket client for relay communication
uuid
UUID generation for identifiers

The agent does not install background services, browser extensions, or kernel modules. It runs as a single user-space process that you can start and stop at any time.

Analytics & telemetry

We collect usage analytics to improve the product. Here's exactly what we track.

Page views Landing page visits with referrer, UTM parameters, browser, OS, and screen size stored
Session events Login, signup, guest session start, and account conversion events stored
Connection events Agent/browser connect and disconnect timestamps with session duration stored
Agent metadata Hostname, OS, agent version on connect stored
Relay counts Number of messages relayed per user (batched, no content) stored
IP addresses Collected with page view events for geographic analytics stored

We never track terminal content, file contents, keystrokes, or AI conversations. Analytics data is used only for product improvement and is not shared with third parties.

Ready to try it?

Get Started

Free to start. No credit card.