Trust model
Appenda keeps a clear split between what runs on your machine, what runs in the cloud for paid workspaces, and what an agent may do without approval.
Local desktop
Free and local testing use SQLCipher-backed workspace storage on the device. Secrets stay in the OS keychain. Do not paste API keys into chat or commits.
Cloud workspaces
Paid cloud workspaces sync significant table history and run provider work in the cloud queue. Product docs do not claim that cloud edition encrypts customer table data at rest.
Agents and approvals
Agents use bounded appenda.* tools. Risky actions (filesystem, terminal,
destructive writes, egress) stay behind workspace permissions and human
approval where the role matrix requires it.
Keys and integrations
Workspace BYOK and integration keys are vaulted. Company ops secrets (Infisical) are separate from customer workspace keys.