The short version
- Monad sends no telemetry, analytics, crash reports, or usage pings. Ever. There is no opt-out because there is nothing to opt out of.
- No account is required. Monad has no sign-up, no license check, and no server of its own that it phones home to.
- All state — sessions, transcripts, memory, credentials, settings — lives on your disk
under
~/.monad. - The daemon binds loopback only by default. A bound loopback port is not an exposed port.
- The traffic that does leave your machine is traffic you asked for: your model provider, and whatever tools you enable.
What leaves the machine, and when
Nothing in this table happens until you configure or invoke it.
There is no background update check.
monad update contacts GitHub only when you run
it.
The model provider is the significant one: an agent turn sends the model whatever is in
its context window. If a file’s contents were read by a tool, they are in the transcript,
and the transcript goes to the provider on the next turn. Choose your provider
accordingly — that is a property of using a hosted model, not of Monad.
Observability is off by default
Monad is instrumented with OpenTelemetry, but the exporter has no default endpoint:http://localhost:6006 (a local Phoenix instance) unless you set it
yourself; that is still your own machine.
Where your data lives
MONAD_HOME overrides the complete data root.
For managed agents, Monad grants the provider the four concrete shared, member,
session, and runtime directories that belong to that runtime. Monad does not grant the
containing project directory as one broad working root. Provider sandbox enforcement
still depends on the selected provider and launch mode; these boundaries do not replace
host operating-system permissions.
Files in a session workspace are collaborative and writable by every managed agent in
that session. Product rules can be narrower. For example, Kanban requires its Product
Design and Tech Design documents to be published by the assigned host from the task’s
canonical session directory; that check is enforced by the Experience API rather than
by a filesystem ACL.
Secrets
- Credentials are never returned by the API. Settings responses mask them;
monad credential listshows only a preview. - Secrets are never written to logs, transcripts, or structured CLI output, and never passed in argv.
auth.jsonis written mode0600and sits inside a vault that the agent’s own filesystem tools are denied — an agent cannot read its way to your keys.- Agent Runtime Credentials go further: generated code receives a per-run sentinel, and the real value is substituted only on the leg to the hosts you allowed. See agent-runtime-credentials.md.
- Windows has no
chmod; the daemon relies on per-user profile ACLs there. Documented rather than pretended-away.
Third-party code
monad license list lists every third-party package in the production dependency graph with
its license. Atom packs, skills, and MCP servers you install are third-party code that
runs with the access you grant it — treat them like installed software, and read
SECURITY.md before installing something you did not write.