Start here

Reviewing llamay for security and compliance

This page is for the person who has to sign off on llamay: what it is, what crosses the network, which controls exist, how to watch each one work on your own machine, and what it does not do. Every claim links to the page with the detail, and most come with a command you can run.

What you are reviewing

What leaves the machine

THE MACHINE RUNNING LLAMAY prompts, answers, contexts stay here model files read here, never executed audit, captures, index written here by default: a daily update check to api.github.com when you pull: Ollama's registry, Hugging Face, or your URL with -oidc-issuer: the directory's signing keys in an app, signed in: llamay's hosted service
The solid line happens without being asked, and LLAMAY_NO_UPDATE_CHECK=1 removes it. The dashed ones happen only when configured or requested.
CallWhenTurn it off
Update check to api.github.com (the public releases repository)At most once a day, from serve, and from run, info and app in a terminalLLAMAY_NO_UPDATE_CHECK=1. The Mac app has its own switch: Check for Updates Automatically.
Model downloadsllamay pull, or POST /api/pull on a serverserve -pull=false removes the download and store-writing routes
Directory signing keysAt startup, and when a token names an unknown key (at most once a minute)Pass the keys as a file: -oidc-jwks jwks.json
TracesOnly with -otlpLeave it unset
llamay's hosted serviceOnly from an app or Studio that is signed in, or a hosted model chosenDo not sign in; local models never use it
Video frames through ffmpegA video request, if ffmpeg is on the PATHIt is a local subprocess limited to the one file; nothing is fetched

To see it for yourself, run the server with the network off: a model on disk still answers. The offline demo records exactly that.

Controls, and how to watch each one work

ConcernControlSee it
Who may callNamed keys, directory tokens (OIDC), or client certificates and smart cardsA request without one: 401, and a line in the audit with actor -. Deploying
Wire protectionTLS 1.2+ in the engine; mutual TLS on requestopenssl s_client -connect host:11435. TLS
AccountabilityA hash-chained audit record of every request, optionally to syslogllamay audit verify reports the first altered or missing record. Audit
Configuration drift-profile enterprise refuses to start without keys, TLS and auditStart it without one and read the refusal. Profile
Need to knowClassification markings checked against each caller's clearance and compartmentsA request above the caller's clearance: 403 naming both. Markings
Document accessLabels on indexed passages; a caller sees only passages whose every label they holdllamay index query -as <caller>. Access labels
Records retentionEncrypted capture of each request and response, readable only with the records office's key; retention and legal holdllamay capture read -audit ties each capture to its audit line. Capture
Data at restContext snapshots, exports, spill files and the document index sealed with AES-256-GCMRestore a sealed snapshot on a server without the key: refused. Sealing
Personal dataRule-based redaction, each kind validated the way it is issuedllamay redact -json. Redaction
Model provenanceAn inventory of every model with the SHA-256 of the exact file, its source and licencellamay inventory -validate -json. Inventory
Integrity of stateA saved context restores only into the same weights, by SHA-256Restore into another model: 409. Same weights
Supply chainSHA256SUMS signed with Sigstore; platform code signaturescosign verify-blob. Verifying a release
Browser exposureNo CORS headers unless -cors names an origin; Studio answers only local host namesA page on another origin gets a network error. Browsers
Prompt injection through markersChat-template markers in user text are tokenized as text, never as control tokensWhat llamay enforces

Where data is kept

WhatWhereProtected by
Model files~/.llamay/models, or /var/lib/llamay/models for the Linux service, or LLAMAY_MODELSFile permissions; content-addressed by SHA-256
Contexts in memoryThe server processClosed after two hours unused (-session-ttl)
Contexts spilled to disk-ctx-spill-dirAlways encrypted: under -context-key, or a key that exists only for the life of the process
Snapshots and exportsWherever the client saves themEncrypted when the server has -context-key
Audit record-auditHash chain; your file permissions
Captures-capture directory, files 0600Encrypted to the records office's public key; the server cannot read them
Document indexllamay index build -oEncrypted with -key, opened by the server's -context-key
App conversationsThe Mac app's Application Support folder; Studio's browser storage; the Windows app's %LOCALAPPDATA%\llamayThe operating system's account protection. llamay does not encrypt them itself.

Cryptography used

These are standard algorithms. The standard llamay build makes no claim of FIPS 140 validation.

What llamay does not do

Evidence you can collect

llamay version                          # the build: revision, kernels, formats, architectures
llamay inventory -validate -json -o inventory.json
llamay audit verify /var/lib/llamay/audit/audit.jsonl
llamay audit who /var/lib/llamay/audit/audit.jsonl
cosign verify-blob --bundle SHA256SUMS.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/AzmxAI/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com SHA256SUMS

Reporting a vulnerability

Write to [email protected]. The address is also in /.well-known/security.txt. The process is on the security page.