{"slug": "declass-is-a-coding-agent-that-keeps-sensitive-context-on-your-machine", "title": "Declass is a coding agent that keeps sensitive context on your machine", "summary": "Declass, a terminal coding agent from developer maximpri, keeps sensitive codebase context on the user's machine by routing questions about private files to a local model while a cloud model writes the code, with every outbound answer checked against known private values. In a recorded session on fictional customer data, none of 13 planted secrets appeared in the 5 requests sent to the cloud. The tool installs via a one-line script to ~/.local/bin on macOS and Linux for ARM64 or x86-64, supports Ollama local models such as qwen3:8b, and can route cloud requests through a ChatGPT Plus or Pro plan via `declass login chatgpt`.", "body_md": "**Frontier AI coding. Private context stays local.**\n\nDeclass is a terminal coding agent where the cloud model never sees your sensitive data. The cloud model writes the code, and a local model on your machine reads that data and answers its questions.\n\nMost coding agents send everything they read to the cloud, including `.env` files, customer data, and logs. With Declass, when the cloud model needs something from your sensitive data, it has to ask the local model. Declass checks every answer before it leaves, so secrets and raw data stay put.\n\nIt still does everything you'd expect from a coding agent, from editing files to running tests to working through tasks end to end. It just does it without handing over the parts of your codebase you can't afford to share.\n\n<sub>A real session on fictional customer data. The bug is fixed, the tests pass, and none of the 13 planted secrets appear in the 5 requests sent to the cloud. Agent work plays at 6× speed. [Recording and evidence](https://github.com/maximpri/declass/blob/main/docs/evidence/recorder-billing-2026-10-06/README.md)</sub>\n\nRunning everything locally would avoid sending anything, but local models are still well behind the best cloud models at writing code. Declass gives you the cloud model's coding and keeps the private context on your machine, with a record of exactly what was sent.\n\nmacOS and Linux, on ARM64 or x86-64:\n\n```\ncurl -fsSL https://raw.githubusercontent.com/maximpri/declass/main/install.sh | bash\n```\n\nThis installs `declass` to `~/.local/bin` and adds it to your `PATH` (pass `--no-modify-path` to skip that). No `sudo` or Rust toolchain needed. Releases are signed with the [Declass release key](https://github.com/maximpri/declass/blob/main/docs/declass-release.pub). This one-line installer checks checksums, which catch corrupted downloads; to also check the signature, add the key to your allowed signers first ([how](https://github.com/maximpri/declass/blob/main/docs/INSTALLATION.md#signed-releases)). For disk images, building from source or verifying signatures, see the [installation guide](https://github.com/maximpri/declass/blob/main/docs/INSTALLATION.md).\n\nOpen a new terminal in your project and run:\n\n```\ndeclass\n```\n\nDeclass has no default models and sends nothing until you choose them. The first time, it opens a setup screen: it shows the API keys in your environment and the model servers on your machine, you pick the cloud model and the local model (or a server elsewhere on your network), review, and save. `declass setup` opens it again. If you don't have a local model yet, install [Ollama](https://ollama.com) and pull one (for example `ollama pull qwen3:8b`), then run `declass doctor --online` to check its context window is big enough.\n\nNo API key? A ChatGPT Plus or Pro plan works instead:\n\n```\ndeclass login chatgpt                     # sign in with your browser and allow Declass to use your plan\ndeclass config preset chatgpt --confirm   # send the cloud model's requests through your plan\n```\n\nRequests go to OpenAI's public API and count against your plan's usage, which you can limit in [ChatGPT settings](https://chatgpt.com/settings/usage). `declass logout chatgpt` signs out.\n\nThen describe the task:\n\n```\nthe billing export counts inactive customers in active_total, fix it\n```\n\nTo make Declass keep going until your tests pass:\n\n```\ndeclass --check 'npm test' \"fix the failing export tests\"\n```\n\n- Ordinary code is sent to the cloud model as it is. Files that match your sensitive patterns (by default `.env*` , keys,`data/**` , CSVs, databases and logs) are not. The cloud model gets their structure (column names, value types, synthetic example rows) and can ask your local model specific questions about them.\n- Everything that goes out, including the local model's answers, is checked against the private values Declass has seen. Secrets and personal data are replaced with placeholders such as `⟨secret:URL_PASSWORD#1⟩` . The local model can't approve its own answers.\n- Commands run in an OS sandbox (Seatbelt on macOS, bubblewrap on Linux) with network access limited to package registries.\n- The Changes panel shows the diff. The Privacy panel shows each request and what was filtered from it. `declass audit show <run>` prints the full log, which is hash-chained so you can check it hasn't been altered.\n\nThis doesn't make leaks impossible. Declass blocks known private values, and the local model also checks its answers for paraphrased details, but that check is a model's judgement, and an answer like \"3 customers are overdue\" still goes out by design. [What is and isn't covered](https://github.com/maximpri/declass/blob/main/docs/SECURE_BY_DESIGN.md)\n\nHybrid is the default. `declass --mode local-only` keeps everything on your machine, at the cost of coding quality.\n\nWithin a session, the badge in the header shows what Declass will do with your next message:\n\n- **BUILD** : edits files and runs commands. This is the normal mode.\n- **PLAN** :`/plan <task>` investigates with read-only tools and saves a plan you can review, edit and approve.`/plan implement rN` carries it out.\n- **GOAL** :`/goal <outcome>` keeps working across turns until the goal is met or its turn limit runs out.\n\nI ran nine coding tasks, each containing planted private data (customer records, credentials, logs, proprietary pricing), three times with Declass and three times with the same cloud model and no protection. Hidden tests scored the code. Here is every run:\n\nMost of the gap between the two averages comes from two Declass runs that scored zero: one produced code that didn't compile, and one was stopped at its time limit. Both are counted.\n\nThe privacy check looks for complete planted values (also base64, hex and URL-encoded) in the recorded requests. It can't detect a secret leaked in pieces or paraphrased. The tasks are mine, it's one cloud model, and three runs per task is a small sample. [Method and full evidence](https://github.com/maximpri/declass/blob/main/docs/evidence/benchmark-54-2026-10-04/README.md) · [Results as a table](https://github.com/maximpri/declass/blob/main/docs/DECLASS_VISUAL_GUIDE.md#results-by-task) · [Raw data](https://github.com/maximpri/declass/blob/main/docs/evidence/benchmark-54-2026-10-04/report.json)\n\n```\ndeclass                                 # start a session\ndeclass \"fix the failing export\"        # start with a task\ndeclass --check 'cargo test' \"fix it\"   # finish only when the check passes\ndeclass --mode local-only               # use only your local model\ndeclass --resume                        # continue the last session\ndeclass run \"fix the export\"            # run once without a conversation\ndeclass privacy                         # show what's sensitive and where requests go\ndeclass audit show <run>                # show everything a run sent to the cloud\ndeclass doctor                          # check your setup\n```\n\nTo give private code less exposure, list it in `.declass/config.toml`:\n\n```\n[sensitivity]\nprotected_paths = [\"src/billing/**\"]   # read only by the local model\n\n[ip]\ninterface_only = [\"src/pricing/**\"]    # the cloud model sees signatures, not bodies\nsealed = [\"src/risk_model/**\"]         # the cloud model only knows the files exist\n```\n\nEvery session also has a cap on frontier requests, and F2 opens the settings. Declass works with MCP servers, language servers, web search and `SKILL.md` skills, all behind the same checks. [Usage guide](https://github.com/maximpri/declass/blob/main/docs/USAGE.md)\n\nCloud: Anthropic, OpenAI, Google Gemini, OpenRouter, z.ai, DeepSeek, xAI, Mistral, Groq, Cerebras, Together, Fireworks and Qwen, or any OpenAI-compatible endpoint. With a ChatGPT Plus or Pro plan you can skip the API key: `declass login chatgpt` ([details](https://github.com/maximpri/declass/blob/main/docs/USAGE.md#chatgpt-plan)).\n\nLocal: Ollama, LM Studio, llama.cpp, vLLM, oMLX, MLX, Jan, GPT4All, KoboldCpp, LocalAI and LiteLLM. The local model needs a context window of about 40K tokens. In hybrid mode it only reads and answers questions, so it doesn't need to be good at coding.\n\nDeclass is an early release. It has over 1,300 tests and fuzzing, and its Rust code forbids `unsafe`, but it hasn't had an outside security review. Read [the security design](https://github.com/maximpri/declass/blob/main/docs/SECURE_BY_DESIGN.md) before using it with real regulated data.\n\nBug reports and \"it didn't work on my setup\" reports help the most right now: [open an issue](https://github.com/maximpri/declass/issues). I'll accept code contributions once the contributor agreement is published ([details](https://github.com/maximpri/declass/blob/main/CONTRIBUTING.md)). Report vulnerabilities privately through a [security advisory](https://github.com/maximpri/declass/security/advisories/new) ([policy](https://github.com/maximpri/declass/blob/main/SECURITY.md)).\n\nCopyright (C) 2026 Maxim Priezjev. Licensed under [GPL-3.0-or-later](https://github.com/maximpri/declass/blob/main/LICENSE). Release archives include the corresponding source and third-party notices ([licensing](https://github.com/maximpri/declass/blob/main/LICENSES.md)).", "url": "https://wpnews.pro/news/declass-is-a-coding-agent-that-keeps-sensitive-context-on-your-machine", "canonical_source": "https://github.com/maximpri/declass", "published_at": "2026-10-07 21:47:02+00:00", "updated_at": "2026-10-07 22:19:40.716428+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-safety"], "entities": ["Declass", "maximpri", "Ollama", "qwen3:8b", "OpenAI", "ChatGPT Plus", "ChatGPT Pro", "Seatbelt"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/declass-is-a-coding-agent-that-keeps-sensitive-context-on-your-machine", "markdown": "https://wpnews.pro/news/declass-is-a-coding-agent-that-keeps-sensitive-context-on-your-machine.md", "text": "https://wpnews.pro/news/declass-is-a-coding-agent-that-keeps-sensitive-context-on-your-machine.txt", "jsonld": "https://wpnews.pro/news/declass-is-a-coding-agent-that-keeps-sensitive-context-on-your-machine.jsonld"}}