Privacy Policy
What leaves the machine.
VeriCommand's governance core runs entirely on your computer. Network access comes from features you turn on or use: sign-in, independent checks and two-agent conflict checks, Ask VeriCommand, Reconcile, checkout, update checks, and usage events if you allow them. Two things can run without a click: while you are signed in, the app checks your plan and credit balance; and once a credential is on this machine, a connected agent can call the MCP server’s one online tool. The statements below are tied to the shipped behavior, not marketing assumptions.
The free core stays local
The governance core — packets, dispatch, the hash-chained record, HOLD, liveness, and prior-art checking — is files on your local disk. The modules that implement it contain no networking code (checked by a static source sweep), and the core operations were run under a test harness that turns any network attempt into a hard failure — the guard never fired (runtime probe). The board and chain never leave this machine unless you enable a hosted feature described below.
- No account is required to run the core.
- The free core does not need an entitlement server and cannot be disabled remotely. If you sign in, the app does check your plan and credit balance with NorthGate (see the table below).
- No crash reporter. Anonymous usage events are off until you turn them on, at first run or in Settings. When on, each event goes to Mixpanel with: its name (such as app launched, task created, run ended, screen opened); fixed-choice details about it (which agent family, which screen, button or shortcut, a run’s, check’s or review’s outcome, which setting changed and your theme, which kind of error card was shown and on which screen, yes/no flags such as whether a repository was chosen); durations and counts as ranges, never exact numbers; the app version and your operating system’s major version (such as Windows 11); the time it happened; a random install ID created when you opt in; a per-event ID; and VeriCommand’s Mixpanel project token. The app asks Mixpanel not to derive a location from your IP address. Never paths, repository or board names, titles, agent output, emails or keys. Update checks run only when you ask; updates are never silently downloaded or installed.
What can leave, and exactly when
Every network path in the product is off by default and requires an explicit action by you to exist at all. Some actions switch on more than one request: once you sign in, the app checks your plan in the background, and once a credential is on this machine, a connected agent can call the MCP server’s one online tool without a click from you. Both are listed below.
| Path | Fires when | Default |
|---|---|---|
| Account sign-in (email link) | You choose Continue in browser and enter your email | Signed-out — local mode works without it |
| Plan, credit balance and sign-in refresh (NorthGate) | While you are signed in: at launch and whenever the app window comes back into focus, the app asks NorthGate’s server for your plan and your credit balance, sending only your sign-in token. It also refreshes that sign-in token with the server. | Only while signed in — signed out, none of this runs |
| Governance services (enforce / verify / context-mesh) | Not offered in 2.4.0-alpha.16, 2.4.0-alpha.17, 2.4.0-alpha.18 or 2.4.0-alpha.19. The setting to point the app at an API base is switched off in the build, and the app’s content security policy blocks those requests. | Not available in this version |
| Auto-audit (second-model review) | Not in this version: there is no switch for it, and nothing in the app starts it. | Not available in this version |
| Independent checks (a model from a different company) | You run a check (free accounts: 3 a month), or Pro runs one automatically after you allow it once. The selected decisions and the result being checked are sent, plus which AI company your agent runs on so a different one checks it, and whether it ran by hand or automatically. NorthGate’s server sends them to Google, OpenAI or Anthropic, by the rule under “Independent checks” below, and to a second of them if the first call fails. | OFF — nothing is sent until you click, or until you say yes to automatic checks on Pro |
| Two-agent conflict checks | You click the check on My work, or on Pro it runs automatically after your one-time yes to automatic checks. It sends the earlier agent’s report (up to 1,000 characters), the later agent’s report together with the list of files both agents changed (up to 20,000 characters), the task IDs and the agents’ names. It goes the same way as an independent check. | OFF — nothing is sent until you click, or until you say yes to automatic checks on Pro |
| Ask VeriCommand (hosted review of a task) | You are signed in and click Ask VeriCommand on a task. It sends the task’s title, subtitle and workflow; your question; where its source lives (the folder path, repository or link you attached) and your notes on it; any source sample you attached (up to about 180,000 characters); the task’s roadmap and proof gates; the recorded decisions; and the recent conversation on the task. It goes to NorthGate’s server, which sends it to OpenAI and Anthropic. What we keep is under “Ask VeriCommand” below. | OFF — nothing is sent until you click |
| Check against recorded decisions (in the artifact view) | You are signed in and click Check against recorded decisions on an agent’s result. It sends the recorded decisions (up to about 180,000 characters) and the agent’s result (up to about 60,000 characters) to NorthGate’s server, which sends them to OpenAI and Anthropic. The same records are kept as for Ask VeriCommand, below. | OFF — nothing is sent until you click |
| Reconcile (the agent’s report against its changes) | You are signed in and click Reconcile on a returned task. It sends up to 40 sentences of the agent’s report, as claims to test, and the evidence: the paths of the changed files, the diff summary, the full diff of the changes (up to 500 KB, which contains your source code), and the pass and fail counts. It goes to NorthGate’s server, which sends it to Anthropic. The server’s redaction step does not work on this path; see “Reconcile” below. | OFF — nothing is sent until you click |
MCP tool flightdeck_drift_compare | A connected agent calls this tool and the MCP server finds a credential on this machine. It sends the decisions, the agent’s result, a task reference and which AI company the agent runs on to NorthGate’s server, which checks them like an independent check. See “The MCP server” below. | Sends nothing without a credential; with one, the agent’s call is enough — no click from you |
| Usage events (Mixpanel) | You say yes at first run or in Settings | OFF |
| Pro checkout (Stripe) | You request checkout | OFF — no billing request exists until you ask for checkout |
| Billing portal (Stripe) | You click Manage subscription. It opens Stripe’s billing portal at billing.stripe.com. | OFF — only when you click |
| Transactional email (Resend) | A qualifying billing, account, or support event requires a message | OFF — no email is sent from ordinary free-core use |
| Release update check | You click Check for updates | OFF — no automatic background download or installation |
| Automation webhooks | Not in this version | Not available in this version |
| conductor CLI | You invoke it | An HTTP client by design. The MCP server is separate and works locally, except the one tool above |
| Hosted web app (app.ai-flightdeck.com) | You choose the hosted shell | Online by definition; the desktop app does not require it |
| Links | You click a link in the app. It opens in your web browser, which contacts that site under its own settings. | Only when you click |
| Your own agents (not a VeriCommand path) | You run a task. VeriCommand starts your own agent, such as Claude Code or Codex, and that agent talks to its own company under your account and that company’s terms. | VeriCommand does not relay that traffic |
What the local core never transmits
The local core never transmits your agent prompts, your agents' responses, or your repository content. Work product leaves the machine only through the hosted features in the table above: independent checks and two-agent conflict checks (which on Pro can run automatically after your one-time yes), Check against recorded decisions, Ask VeriCommand, Reconcile, and the MCP tool flightdeck_drift_compare (which a connected agent can call on its own once a credential is on the machine). Separately, the agents you run talk to their own companies directly; that is their traffic, not VeriCommand’s.
When you enable hosted features
If you sign in or use a hosted feature, we process — as your service provider — only what those features need:
- Identity: the email address you enter to sign in, used to authenticate you.
- Credentials: your sign-in token, sent with each signed-in request so the server knows it is you. The MCP tool
flightdeck_drift_comparesends your account token or, if it finds none, the whole text of your Pro licence file (see “The MCP server” below). - Governance records: the chain records work about work — task titles, states, hashes, timestamps, and agent names. You choose what goes into packet text; we recommend keeping sensitive identifiers out of titles.
We use this data only to provide the features you turned on. We do not sell it, and we do not use your content to train models.
Independent checks, billing, and your Pro plan
Independent checks are intentionally not a zero-egress feature. When a check runs (you click it, or on Pro it runs automatically after you allowed it once), VeriCommand sends the selected recorded decisions and the agent result being checked, plus which AI company your agent runs on so a different one checks it and whether the check ran by hand or automatically, to an endpoint on NorthGate's server. A two-agent conflict check uses the same endpoint: it sends the earlier agent’s report as the decision (up to 1,000 characters), the later agent’s report followed by “Files both changed:” and those files’ paths (up to 20,000 characters), the task IDs and the agents’ names. The MCP tool flightdeck_drift_compare uses it too (see “The MCP server” below).
Which company checks it. The server sends the check to the first of Google, OpenAI and Anthropic, currently in that order (a server setting), that is not the company your agent runs on, as the app reports it. If that call fails, it tries the next one that is not your agent’s company. So one check reaches at most two companies: an agent on Google is checked by OpenAI, then Anthropic; an agent on OpenAI by Google, then Anthropic; an agent on Anthropic by Google, then OpenAI. Perplexity is on the server’s list of allowed checkers but is not reached with the current order. Nothing is removed from the text before it goes to that company, and the company processes it under its own service terms, including its own retention.
What we keep, and for how long. The server does not store the decisions, the agent’s result or the checking model’s answer after the request. It does keep:
- per-account counts of checks and seals, by month, day and kind (including automatic checks, and attempts that failed);
- a cost record for each check: a random request ID, the estimated and actual cost, its status and its times, with no content from the check;
- daily usage counters for your account, with no content: the number of calls, kept 90 days, and the number per endpoint, kept 30 days (hourly counters are kept 2 hours);
- log lines: one for every successful check (which company and model answered, the cost, token counts and how many contradictions were found), and more when something fails, including error messages returned by the model company. Some of these lines carry your account identifier.
The per-account counts and cost records are not deleted automatically. Log lines are kept for as long as our cloud logging keeps them; our code does not set a limit. To ask for your records to be deleted, contact us (below).
Outside companies that can receive your data, and for what:
- Stripe processes checkout, subscription status, the billing portal, and payment-related information. VeriCommand does not receive full card details.
- Account entitlement is checked by NorthGate when a signed-in user requests a hosted Pro operation, and, while you are signed in, at launch and whenever the app window comes back into focus. Cancellation, failed payment, refund, or administrative revocation can disable hosted Pro access; none of those events disables the free local core.
- Google, OpenAI and Anthropic run independent checks, two-agent conflict checks and calls to the MCP tool
flightdeck_drift_compare, chosen by the rule above, under their own service terms. - OpenAI and Anthropic process Ask VeriCommand and Check against recorded decisions requests, including any source sample you attached, to write the review, under their own service terms.
- Anthropic processes Reconcile requests, including the full diff of the agent’s changes, under its own service terms (see “Reconcile” below).
- Mixpanel processes anonymous usage events, only if you turn them on (see "The free core stays local" above).
- Resend processes the recipient email address and transactional message when VeriCommand needs to send an account, billing, support, or compatibility notice.
- Legacy signed licences may be accepted during the transition to account-based entitlement. They are a compatibility path, not the primary activation model. The MCP tool
flightdeck_drift_comparecan send a Pro licence file’s whole text to NorthGate as its credential (see below).
Ask VeriCommand
Ask VeriCommand can send your source files: a sample you attach to the task. (Reconcile, below, also sends source code, as the diff of an agent’s changes.) When you are signed in and click Ask VeriCommand, the app sends the request listed in the table above, including any source sample you attached (up to about 180,000 characters), to NorthGate’s server. The server removes personal data and keys it can recognize, such as email addresses, phone numbers and card numbers, then sends the rest to OpenAI and Anthropic. Each writes a review, and the server combines them into one answer. The models may also run lookups on public sources, such as a web search (DuckDuckGo), Wikipedia, arXiv, Crossref, news feeds or SEC filings, using search terms they write. The server may also check up to eight short facts from the answer against Wikipedia and Wikidata.
What we keep, and for how long. For each review we keep a record with the first 500 characters of the request (the task text, not the source sample; for the Check against recorded decisions button, the start of the agent’s result) and the first 500 characters of the answer, plus the time, your account, which companies answered, the scores and what the review cost. If the server finds personal data or a key in the request, it also keeps a note of the type found and the first 200 characters of the request as received, before removal; with a source sample attached, those characters come from the start of the sample. These records are append-only and are not deleted automatically. To ask for yours to be deleted, contact us (below).
The Check against recorded decisions button in the artifact view uses the same server path: it sends your recorded decisions and the agent’s result, OpenAI and Anthropic write the comparison, and the same records are kept.
Reconcile
Reconcile tests what an agent said it did against what it actually changed. When you are signed in and click Reconcile on a returned task, the app sends NorthGate’s server up to 40 sentences from the agent’s report, as claims, and the evidence: the paths of the changed files, the diff summary, the full diff of the changes, up to 500 KB, and the pass and fail counts. The diff contains your source code.
The server sends each claim to Anthropic (by default its Claude Haiku model) in a request of its own, and every one of those requests carries the whole evidence. With 40 claims, the full diff goes to Anthropic 40 times. The requests are marked for Anthropic’s short-lived prompt cache, and Anthropic processes them under its own service terms. If the server cannot get an answer from Anthropic, it falls back to a simpler word-matching check on the server.
Redaction does not work on this path. The server has a step meant to remove personal details before the model sees the text. In the current server version it does not: each request to Anthropic contains your original text, a redacted copy of it, and every personal detail the step detected (such as an email address) listed again on its own. Treat everything Reconcile sends as going to Anthropic unredacted. This is a bug in our server code.
What we keep, and for how long. The server stores none of the claims, the evidence or the verdicts. It sends back each claim with a verdict, a confidence and a short reason of up to 300 characters, and keeps only: the same content-free usage counters as for independent checks (90 days, 30 days and 2 hours); a short-lived rate-limit counter for your account; and, when something fails, log lines that can include an error message from Anthropic and up to 120 characters of the model’s reply. Log lines are kept for as long as our cloud logging keeps them; our code does not set a limit.
The MCP server
The MCP server that ships with VeriCommand works on files on your machine, with one exception: the flightdeck_drift_compare tool. When a connected agent calls it and the MCP server finds a credential, it sends the decisions, the agent’s result, a task reference and which AI company the agent runs on to NorthGate’s server, which checks them the way it checks an independent check: the same company rule and the same records kept. No click from you is needed; the agent’s call is enough. With no credential, the tool sends nothing.
It looks for a credential in this order: the FLIGHTDECK_ACCOUNT_TOKEN environment variable, ~/.flightdeck/session.json, ~/.flightdeck/account-token, and, if none of those, a Pro licence file at ~/.flightdeck/license.json. In that last case, the licence file’s whole text is sent to NorthGate as the credential header.
Update checks
VeriCommand does not silently update itself. When you click Check for updates, the desktop contacts NorthGate's release feed to read current version metadata. If a signed update is available, you choose whether to download it and whether to restart and install it. The updater validates the publisher signature through the signed installer path; an update check does not transmit your board, prompts, agent returns, or repository content. The release feed is served from this website, so an update check — and any update you then download inside the app — is recorded in the download records described under "This website" below, with the same fields, including the daily hash of your IP address, your network and your country.
This website
- Early access: this site still accepts early-access sign-ups, and we keep the ones already collected. For each we store the email address, the time and a short label for where the sign-up came from, and use them only to contact that person about availability. They are not deleted automatically; ask us (contact below) and we will delete yours.
- Hosting: the site is served by Cloudflare, which processes standard request metadata (such as IP address and user agent) to deliver and protect the site.
- Downloads and update checks: when you download VeriCommand from this site — and when the app checks for updates or downloads one, because its release feed is served from here — we record the file requested, the time, the request type (GET or HEAD, and whether it asked for only part of the file) and the response status, the type of browser or client without its version, the network (its ASN number and name) and country the request came from, the hostname of the referring site, and a keyed one-way hash of your IP address — for IPv6, of its /64 network prefix — that changes every day. We never store the IP address itself. If the request came from our download button, the link carries a random token generated by that click, and we store that token on the download record and again on a separate click record with the date and a time rounded to the minute, so we can tell downloads that followed a button click from automated ones. We keep these records for up to 180 days — they are deleted as later requests come in — and use them only to count downloads and to tell people apart from automated traffic.
- Visits: this site's own script records one row per page view or button click: the time, the page, the kind of site that sent you (for example "google" or "direct", not the full address), any utm_source tag in the link, which download or checkout button you clicked, and a random ID that lasts only as long as that browser tab. No cookies and no IP address. We keep these rows for up to 400 days and use them only to count visits.
- We run no third-party ad networks and no cross-site tracking, and we do not sell visitor data.
How these claims are checked
The local-first statements above were checked against the shipped source on 3 August 2026 — a static sweep for network imports and a runtime probe under a socket guard, with method and limits recorded in an internal audit. The probe covered the core library paths, not every process end to end; a full session-length packet capture is named as open work. The rows added or changed on 25 September 2026 were checked against the 2.4.0-alpha.16 source that day, including a sweep of every network path in the desktop app and its MCP server; the Ask VeriCommand, independent-check and Reconcile sections were also checked against the server source that day. If this page and the code ever disagree, the code is what actually runs, and this page is the defect — tell us and we will fix it.
Education deployments (FERPA)
On a lab machine running only the free core, with no one signed in and no credential on it, the governance record stays on that machine and VeriCommand sends no student work or agent output anywhere. That covers VeriCommand’s own paths only: the agents students run talk to their own companies directly (see “Your own agents” in the table above), and that traffic needs its own review. The moment hosted features are enabled, records that may reference student work become data held by a processor, and a FERPA review should happen before enablement, not after. We state this so it is a planning input, not a discovery.
Your choices and contact
You can ask what data we hold about you, correct it, or have it deleted. Because the core keeps your governance data on your own machine, most of it is already in your hands; for the rest, or any privacy question, contact:
NorthGate Strategic LLC
support@northgatestrategic.com
Changes
If we change what the product or this site does with data, we will update this page and its effective date. Material changes to hosted features will be called out, not buried.