Start here
Reviewing llamay for security and compliance
This page is for the person who has to sign off on llamay: what it is, what crosses the network, which controls exist, how to watch each one work on your own machine, and what it does not do. Every claim links to the page with the detail, and most come with a command you can run.
What you are reviewing
- One static binary per platform. It loads GGUF model files, runs them on the CPU or a GPU, and serves an HTTP API. Model files are data: llamay executes nothing from them.
- No telemetry. There is no usage reporting and no endpoint that collects prompts.
- The source is not public. What you can inspect is the released binary, its behaviour, and the signatures on the release. Builds are published at github.com/AzmxAI/llamay-releases.
- Not assessed. llamay has not been independently assessed, certified or accredited against any framework. The controls below are features; whether they meet your framework is your assessor's call.
What leaves the machine
LLAMAY_NO_UPDATE_CHECK=1 removes it. The dashed ones happen only when configured or requested.| Call | When | Turn it off |
|---|---|---|
Update check to api.github.com (the public releases repository) | At most once a day, from serve, and from run, info and app in a terminal | LLAMAY_NO_UPDATE_CHECK=1. The Mac app has its own switch: Check for Updates Automatically. |
| Model downloads | llamay pull, or POST /api/pull on a server | serve -pull=false removes the download and store-writing routes |
| Directory signing keys | At startup, and when a token names an unknown key (at most once a minute) | Pass the keys as a file: -oidc-jwks jwks.json |
| Traces | Only with -otlp | Leave it unset |
| llamay's hosted service | Only from an app or Studio that is signed in, or a hosted model chosen | Do not sign in; local models never use it |
Video frames through ffmpeg | A video request, if ffmpeg is on the PATH | It is a local subprocess limited to the one file; nothing is fetched |
To see it for yourself, run the server with the network off: a model on disk still answers. The offline demo records exactly that.
Controls, and how to watch each one work
| Concern | Control | See it |
|---|---|---|
| Who may call | Named keys, directory tokens (OIDC), or client certificates and smart cards | A request without one: 401, and a line in the audit with actor -. Deploying |
| Wire protection | TLS 1.2+ in the engine; mutual TLS on request | openssl s_client -connect host:11435. TLS |
| Accountability | A hash-chained audit record of every request, optionally to syslog | llamay audit verify reports the first altered or missing record. Audit |
| Configuration drift | -profile enterprise refuses to start without keys, TLS and audit | Start it without one and read the refusal. Profile |
| Need to know | Classification markings checked against each caller's clearance and compartments | A request above the caller's clearance: 403 naming both. Markings |
| Document access | Labels on indexed passages; a caller sees only passages whose every label they hold | llamay index query -as <caller>. Access labels |
| Records retention | Encrypted capture of each request and response, readable only with the records office's key; retention and legal hold | llamay capture read -audit ties each capture to its audit line. Capture |
| Data at rest | Context snapshots, exports, spill files and the document index sealed with AES-256-GCM | Restore a sealed snapshot on a server without the key: refused. Sealing |
| Personal data | Rule-based redaction, each kind validated the way it is issued | llamay redact -json. Redaction |
| Model provenance | An inventory of every model with the SHA-256 of the exact file, its source and licence | llamay inventory -validate -json. Inventory |
| Integrity of state | A saved context restores only into the same weights, by SHA-256 | Restore into another model: 409. Same weights |
| Supply chain | SHA256SUMS signed with Sigstore; platform code signatures | cosign verify-blob. Verifying a release |
| Browser exposure | No CORS headers unless -cors names an origin; Studio answers only local host names | A page on another origin gets a network error. Browsers |
| Prompt injection through markers | Chat-template markers in user text are tokenized as text, never as control tokens | What llamay enforces |
Where data is kept
| What | Where | Protected by |
|---|---|---|
| Model files | ~/.llamay/models, or /var/lib/llamay/models for the Linux service, or LLAMAY_MODELS | File permissions; content-addressed by SHA-256 |
| Contexts in memory | The server process | Closed after two hours unused (-session-ttl) |
| Contexts spilled to disk | -ctx-spill-dir | Always encrypted: under -context-key, or a key that exists only for the life of the process |
| Snapshots and exports | Wherever the client saves them | Encrypted when the server has -context-key |
| Audit record | -audit | Hash chain; your file permissions |
| Captures | -capture directory, files 0600 | Encrypted to the records office's public key; the server cannot read them |
| Document index | llamay index build -o | Encrypted with -key, opened by the server's -context-key |
| App conversations | The Mac app's Application Support folder; Studio's browser storage; the Windows app's %LOCALAPPDATA%\llamay | The operating system's account protection. llamay does not encrypt them itself. |
Cryptography used
- TLS from Go's standard library, version 1.2 minimum.
- Sealed contexts and the index: AES-256-GCM in 1 MiB authenticated chunks, with a 256-bit key you supply.
- Capture: ephemeral ECDH P-256 per record, HKDF-SHA-256, AES-256-GCM.
- Audit chain and key storage: SHA-256.
- Directory tokens: RS256/384/512, PS256/384/512 and ES256/384/512.
noneand shared-secret algorithms are refused.
These are standard algorithms. The standard llamay build makes no claim of FIPS 140 validation.
What llamay does not do
- No independent assessment or accreditation, and no claim to one.
- No SAML or LDAP. Identity is keys, OIDC tokens or client certificates.
- No revocation checking of client certificates (no CRL or OCSP).
- No key management service or HSM integration. Keys are files you provide and protect.
- No reading of content for classification. A marking is the caller's declaration, checked against their clearance. It is not a cross-domain solution.
- No detection of names or free-text personal data. Redaction finds patterns that can be validated, not names or addresses written in prose.
- No encryption of app conversation history beyond what the operating system provides.
- No per-request rate limiting by caller. The queue is shared; a full queue answers
429to everyone.
Evidence you can collect
llamay version # the build: revision, kernels, formats, architectures
llamay inventory -validate -json -o inventory.json
llamay audit verify /var/lib/llamay/audit/audit.jsonl
llamay audit who /var/lib/llamay/audit/audit.jsonl
cosign verify-blob --bundle SHA256SUMS.sigstore.json \
--certificate-identity-regexp '^https://github\.com/AzmxAI/' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com SHA256SUMS
Reporting a vulnerability
Write to [email protected]. The address is also in
/.well-known/security.txt. The
process is on the security page.