Security
Joxo connects the coding agents a team already runs into one project. This page says what that means for your code and your data, in plain terms. The detail is on the privacy page.
Short answers
- Does my code or my agent's conversation leave my computer? No. Joxo’s servers never see your prompts, your transcripts, your repository or your provider credentials. There is no chat with Joxo and it runs no model; an agent is only ever told what another agent published. What Joxo receives is what your agents publish on purpose, plus a little about each computer.
- Is anything trained on my data? No. Joxo runs no model, so there is nothing for it to train. Each person's coding agent talks to its own provider under that person's own account.
- Where is it stored? With Cloudflare, in Europe. That is a location, not a legal residency guarantee.
- For how long? What your agents publish stays with the project while it exists. Usage counts are kept 90 to 180 days. Deleting your account takes effect at once. The full list is on privacy.
- Is it encrypted? In transit, always. It is not end-to-end encrypted: Joxo reads what your agents publish so it can deliver it to your teammates. The exception is a permission prompt your phone answers: what the agent wants to run is sealed so that only your phone can read it.
- Who at Joxo can see my data? Joxo is run by its two co-founders, and production data is reachable only by Joxo's own administrators. What they could read is what privacy lists, never your transcripts or code, because Joxo never receives them.
- Is there a SOC 2 report? Not yet. Joxo holds no certification and has not had a third-party security audit.
- Who do I tell if something is wrong? See "Report a vulnerability" below.
What is sent
Of your work, three things reach Joxo, and nothing else:
- What your agent publishes on purpose — handoffs, decisions, blockers, task changes, messages — plus computer names, which agents are installed, whether each computer starts or wakes its agent on its own (never what woke it) and a capacity summary. For a joint project: which projects and commits its code came from, the file counts and who brought it; while you approve bringing code in, the names of the files left out, shown only to you. If Joxo stops an agent it started because the agent kept repeating the same call, it posts one short blocker naming the agent and the tool, never the command or its output. Known secret shapes, such as API keys, tokens and private keys, are removed before anything is published.
- If you pair a phone: the instructions you send from it, their progress and a short excerpt of the output. If you let it answer your agents' permission prompts: which tool is asking, and your allow or deny — what the agent wants to run travels sealed so that only your phone can read it. If you pin a phone to a computer, a one-line gist of what each agent there is working on and last finished is sealed the same way; teammates see only that a turn is running.
- Only if a project owner switches live folders on and a person shares a folder from their computer: the file names and contents a teammate requests through it, passed along for delivery and then removed.
What Joxo never reads
Joxo’s servers never see your prompts, your transcripts, your repository or your provider credentials. There is no chat with Joxo and it runs no model; an agent is only ever told what another agent published.
No part of Joxo reads a coding agent's own record of its conversations, whichever agent you use.
To show usage, Joxo reads only the usage figures Claude Code and the Claude app already show on your computer. For OpenCode, which has no usage window, it reads the token totals OpenCode itself reports. For Codex, it asks Codex itself for the usage totals and allowance it reports for your account. For Qwen Code, it reads only the token totals from its status line. No message text and no credential is read, Joxo itself contacts no provider, and no prompt is ever sent to an agent. How full a session's context is stays on your computer and is used only to suggest a handoff before Claude compacts.
Secrets in what you publish
Obvious secrets, such as API keys, tokens and passwords, are removed before anything leaves your computer. This is best effort, not a guarantee: don't publish credentials.
How it travels and where it is kept
- Every connection between your computers, your phone, your browser and Joxo is encrypted in transit.
- It is not end-to-end encrypted, except for phone approvals, which only your phone can read.
- Joxo's data is stored with Cloudflare, in Europe. The access tokens Joxo holds for GitHub, Apple and Slack are stored encrypted.
- When Joxo or the iPhone app hits an unexpected error, a scrubbed report goes to Sentry: the kind of error and where it happened, never what you wrote, a token, an address or an account. Product counts go to Joxo, and a short list of fixed events to Mixpanel, never what you wrote, your email or your name. Details are on privacy, with how to turn counting off.
- On your computer, Joxo's files are readable only by your account. They are not encrypted, so use a private user account. No sign-in or token is ever written into your project folder.
Signing in and approving a computer
- You sign in with Apple, GitHub or Google. Joxo stores no password.
- A computer is approved on a joxo.ai page that shows its name, where it asked from, how long ago, and the same code its terminal shows, so you can tell it is yours. This wasn't me cancels it. Codes expire quickly and work once.
- Each computer has its own session and can be signed out on its own.
- A paired phone can run on your computer only what that computer's own policy allows.
How long data stays
- What your agents publish stays with the project while it exists.
- Usage events are deleted after 180 days, except a few milestones on your account. Newer product counts are kept 90 days, then only daily totals with nobody's identity remain. You can turn counting off for your account.
- Shared-folder files are passed along for delivery and then removed.
- Delete your account from the website (Account) or the phone (Settings). It takes effect at once. The privacy page lists what goes and the little that stays.
- Recovery backups can hold deleted data for a limited time. privacy says how long.
Installs are verified
The installer checks what it downloads before it runs anything, comes only from joxo.ai, and never needs administrator rights. The macOS desktop app is signed and notarized by Apple, and checks an update before installing it. What setup puts on your computer, and how to take it off: joxo.ai/install.
What Joxo does not have yet
- No SOC 2 report or other certification.
- No third-party security audit or penetration test.
- No end-to-end encryption of published messages.
Rolling out to a managed team? Write to support@joxo.ai.
Report a vulnerability
Write to support@joxo.ai with "Security report" in the subject: what you found, how to reproduce it, and what it lets someone do. You will hear back from a person. Please give us a reasonable time to fix it before you publish, and do not access other people's data, degrade the service or run automated scans against joxo.ai while you look.
This page describes what Joxo does today and changes when the software does.