Alden is trusted with your computer and your logins.
Every action routes through the Governance Engine before it runs, checked against Always / Ask Every Time / Never rules you set across authentication, browser automation, and system actions.
The model runs locally on your own device. Your files, your conversations, and what you ask Alden to do stay on your machine rather than being sent anywhere for processing.
Alden creates a folder called AldenWorkspace on your Desktop during setup. Put the files you want it to work on there. Alden reads what you place in that folder; it does not go looking elsewhere on your Mac. If you skip this during setup you can create it later, in Settings → Permissions.
macOS makes an app ask before it can reach anything sensitive, and every prompt you see comes with a reason. This is the complete list.
What matters as much is the list Alden never asks for:
Declining any of them is allowed. The feature that needed it stops working. Everything else carries on, and you can grant it later from Settings → Permissions.
Alden is unusual among assistants: it runs on your own machine, holds the keys to your accounts, and can act without you watching. That shapes what we defend against.
The model runs locally, so the usual risk of a cloud assistant, your prompts and files sitting on someone else's servers, does not apply to anything you say out loud. Voice never reaches a cloud model on any plan. That is an architectural rule rather than a licence check, because a microphone picks up people who never agreed to anything, and no policy can consent on their behalf.
Paid plans offer a model selector in chat. Picking a cloud model there sends that conversation to the company you chose, and nothing else is sent anywhere, see the privacy policy for what is sent and to whom.
A second question replaces the one that no longer applies, and it is the harder one: what can software on your machine be talked into doing? The Governance Engine exists for exactly that.
An assistant that reads web pages and email can be fed instructions by the content it reads. We treat that as a real attack, not a curiosity. The mitigation isn't cleverness about spotting malicious text, it's that the consequential actions are gated regardless of what convinced Alden to attempt them. Injected text can't grant itself file access or approve its own payment.
Report to alden@quantintelligence.co with "Security" in the subject, and give us a chance to fix it before disclosing publicly.
What helps most, specific to Alden:
Please don't test against other people's accounts or data. We won't pursue researchers acting in good faith within that boundary. We don't run a paid bounty programme today; this page will say so if that changes.
What's collected and how long it's kept is in Alden's privacy policy. The developer API is served by our infrastructure rather than your machine, and is covered separately there.