cd /news/ai-agents/declass-is-a-coding-agent-that-keeps… · home › topics › ai-agents › article
[ARTICLE · art-147194] src=github.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Declass is a coding agent that keeps sensitive context on your machine

Declass, a terminal coding agent from developer maximpri, keeps sensitive codebase context on the user's machine by routing questions about private files to a local model while a cloud model writes the code, with every outbound answer checked against known private values. In a recorded session on fictional customer data, none of 13 planted secrets appeared in the 5 requests sent to the cloud. The tool installs via a one-line script to ~/.local/bin on macOS and Linux for ARM64 or x86-64, supports Ollama local models such as qwen3:8b, and can route cloud requests through a ChatGPT Plus or Pro plan via `declass login chatgpt`.

read6 min views1 publishedOct 7, 2026
Declass is a coding agent that keeps sensitive context on your machine
Image: Michielbdejong (auto-discovered)

Frontier AI coding. Private context stays local.

Declass is a terminal coding agent where the cloud model never sees your sensitive data. The cloud model writes the code, and a local model on your machine reads that data and answers its questions.

Most coding agents send everything they read to the cloud, including .env files, customer data, and logs. With Declass, when the cloud model needs something from your sensitive data, it has to ask the local model. Declass checks every answer before it leaves, so secrets and raw data stay put.

It still does everything you'd expect from a coding agent, from editing files to running tests to working through tasks end to end. It just does it without handing over the parts of your codebase you can't afford to share.

<sub>A real session on fictional customer data. The bug is fixed, the tests pass, and none of the 13 planted secrets appear in the 5 requests sent to the cloud. Agent work plays at 6× speed. Recording and evidence</sub>

Running everything locally would avoid sending anything, but local models are still well behind the best cloud models at writing code. Declass gives you the cloud model's coding and keeps the private context on your machine, with a record of exactly what was sent.

macOS and Linux, on ARM64 or x86-64:

curl -fsSL https://raw.githubusercontent.com/maximpri/declass/main/install.sh | bash

This installs declass to ~/.local/bin and adds it to your PATH (pass --no-modify-path to skip that). No sudo or Rust toolchain needed. Releases are signed with the Declass release key. This one-line installer checks checksums, which catch corrupted downloads; to also check the signature, add the key to your allowed signers first (how). For disk images, building from source or verifying signatures, see the installation guide.

Open a new terminal in your project and run:

declass

Declass has no default models and sends nothing until you choose them. The first time, it opens a setup screen: it shows the API keys in your environment and the model servers on your machine, you pick the cloud model and the local model (or a server elsewhere on your network), review, and save. declass setup opens it again. If you don't have a local model yet, install Ollama and pull one (for example ollama pull qwen3:8b), then run declass doctor --online to check its context window is big enough.

No API key? A ChatGPT Plus or Pro plan works instead:

declass login chatgpt                     # sign in with your browser and allow Declass to use your plan
declass config preset chatgpt --confirm   # send the cloud model's requests through your plan

Requests go to OpenAI's public API and count against your plan's usage, which you can limit in ChatGPT settings. declass logout chatgpt signs out.

Then describe the task:

the billing export counts inactive customers in active_total, fix it

To make Declass keep going until your tests pass:

declass --check 'npm test' "fix the failing export tests"
  • Ordinary code is sent to the cloud model as it is. Files that match your sensitive patterns (by default .env* , keys,data/** , CSVs, databases and logs) are not. The cloud model gets their structure (column names, value types, synthetic example rows) and can ask your local model specific questions about them.
  • Everything that goes out, including the local model's answers, is checked against the private values Declass has seen. Secrets and personal data are replaced with placeholders such as ⟨secret:URL_PASSWORD#1⟩ . The local model can't approve its own answers.
  • Commands run in an OS sandbox (Seatbelt on macOS, bubblewrap on Linux) with network access limited to package registries.
  • The Changes panel shows the diff. The Privacy panel shows each request and what was filtered from it. declass audit show <run> prints the full log, which is hash-chained so you can check it hasn't been altered.

This doesn't make leaks impossible. Declass blocks known private values, and the local model also checks its answers for paraphrased details, but that check is a model's judgement, and an answer like "3 customers are overdue" still goes out by design. What is and isn't covered

Hybrid is the default. declass --mode local-only keeps everything on your machine, at the cost of coding quality.

Within a session, the badge in the header shows what Declass will do with your next message:

  • BUILD : edits files and runs commands. This is the normal mode.
  • PLAN :/plan <task> investigates with read-only tools and saves a plan you can review, edit and approve./plan implement rN carries it out.
  • GOAL :/goal <outcome> keeps working across turns until the goal is met or its turn limit runs out.

I ran nine coding tasks, each containing planted private data (customer records, credentials, logs, proprietary pricing), three times with Declass and three times with the same cloud model and no protection. Hidden tests scored the code. Here is every run:

Most of the gap between the two averages comes from two Declass runs that scored zero: one produced code that didn't compile, and one was stopped at its time limit. Both are counted.

The privacy check looks for complete planted values (also base64, hex and URL-encoded) in the recorded requests. It can't detect a secret leaked in pieces or paraphrased. The tasks are mine, it's one cloud model, and three runs per task is a small sample. Method and full evidence · Results as a table · Raw data

declass                                 # start a session
declass "fix the failing export"        # start with a task
declass --check 'cargo test' "fix it"   # finish only when the check passes
declass --mode local-only               # use only your local model
declass --resume                        # continue the last session
declass run "fix the export"            # run once without a conversation
declass privacy                         # show what's sensitive and where requests go
declass audit show <run>                # show everything a run sent to the cloud
declass doctor                          # check your setup

To give private code less exposure, list it in .declass/config.toml:

[sensitivity]
protected_paths = ["src/billing/**"]   # read only by the local model

[ip]
interface_only = ["src/pricing/**"]    # the cloud model sees signatures, not bodies
sealed = ["src/risk_model/**"]         # the cloud model only knows the files exist

Every session also has a cap on frontier requests, and F2 opens the settings. Declass works with MCP servers, language servers, web search and SKILL.md skills, all behind the same checks. Usage guide

Cloud: Anthropic, OpenAI, Google Gemini, OpenRouter, z.ai, DeepSeek, xAI, Mistral, Groq, Cerebras, Together, Fireworks and Qwen, or any OpenAI-compatible endpoint. With a ChatGPT Plus or Pro plan you can skip the API key: declass login chatgpt (details).

Local: Ollama, LM Studio, llama.cpp, vLLM, oMLX, MLX, Jan, GPT4All, KoboldCpp, LocalAI and LiteLLM. The local model needs a context window of about 40K tokens. In hybrid mode it only reads and answers questions, so it doesn't need to be good at coding.

Declass is an early release. It has over 1,300 tests and fuzzing, and its Rust code forbids unsafe, but it hasn't had an outside security review. Read the security design before using it with real regulated data.

Bug reports and "it didn't work on my setup" reports help the most right now: open an issue. I'll accept code contributions once the contributor agreement is published (details). Report vulnerabilities privately through a security advisory (policy).

Copyright (C) 2026 Maxim Priezjev. Licensed under GPL-3.0-or-later. Release archives include the corresponding source and third-party notices (licensing).

── more in #ai-agents 4 stories · sorted by recency
── more on @declass 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/declass-is-a-coding-…] indexed:0 read:6min 2026-10-07 · —