Skip to content

Security should be visible in the decisions.

Charles is designed to make authority, working scope, account state, and provider boundaries understandable before an agent acts.

Your workspace stays explicit

Charles shows the exact folder an agent is working in. New folders require a deliberate selection, and broad home-folder access receives an additional warning before it is granted.

Provider access stays local

Codex, Claude Code, Kimi Code, and Grok use the provider connection already authorized on your device. Charles does not copy those CLI credentials into your Charles account.

Account access is revocable

Desktop devices are linked to a Charles account and checked against current membership. Signing out, revoking a device, or losing paid access stops privileged local service work.

Unfinished capabilities stay closed

A configured key or a visible interface is not treated as proof that a service is safe to publish. Billing, updates, media generation, backups, and operations each have separate launch gates.

Public release standard

We do not ask customers to bypass operating-system protections. Public desktop downloads will be published only through the supported, signed release path for that platform.

Security reports can be sent to support+charles@sovrintech.com. Please avoid including passwords, API keys, private source code, or customer data in the first message.