API Profile Guard

Plain-language policy

Privacy for local API checks

Effective August 28, 2026

Files the CLI uses

API Profile Guard reads the policy, environment file, and optional request body you name.

It writes decision receipts only to the local path in your policy.

Data kept out of receipts

Receipts exclude environment values, headers, query strings, and request bodies.

They include the environment name, fingerprint, method, host, path, decision codes, credential label, and time.

Approved network requests

APG checks policy before starting your client. A blocked run starts no client and opens no client connection.

Your approved client command controls any request made after a passing check.

Browser sample data

The browser sample sends no input to a server. Demo state uses only a demo: session-storage key.

Leaving the demo removes that key. It does not read or change other browser storage.

Static website delivery

The website loads no analytics, advertisements, cookies, or third-party runtime scripts.

A service worker caches public site files so the sample can reload offline.

Contact

Open a privacy issue in the public repository. Do not include secrets or production request details.