Inspect the evidence, including the limits.

A gateway that guards your agent should not ask for blind trust. This ledger separates what LaunchZero claims, what you can inspect now, and where the boundary stops.

Local control

LaunchZero's policy, Activity, and managed secret store stay on your machine.

Current evidence

LaunchZero is local-first, with no LaunchZero cloud in the enforcement path. Keys managed through LaunchZero live in its local encrypted store; provider credentials remain within the agent's configured trust boundary.

Limit

LaunchZero cannot make a fully compromised operating system safe.

Source and license

The gateway guarding the agent is itself open to inspection.

Current evidence

The complete local-first gateway source is public under AGPL-3.0.

Limit

Public source makes review possible; it does not replace your own evaluation.

Maker

The organization responsible for LaunchZero is named and reachable.

Current evidence

LaunchZero is a Security Research Group product.

Limit

LaunchZero remains the product; the maker relationship is supporting evidence.

Release

Published artifacts inherit their status from the release source of truth.

Current evidence

Release 2026.07.25 · is the current data-driven build. A checksum manifest and detached signature are published.

Limit

Release claims follow the fields and capability flags in the release source of truth; no additional signing or build guarantees are implied.

Vulnerability disclosure

Good-faith security reports have a direct destination.

Current evidence

Send the issue, impact, and clear reproduction steps to the dedicated disclosure address.

Inspect or verify

Report a vulnerabilityreports@securityresearch.us

Limit

No response-time or remediation-time commitment is asserted here.

Explicit limits

LaunchZero governs mediated requests; it does not claim to solve every host risk.

Current evidence

It policy-gates monitored tools and managed integrations, including file and network access through those governed paths, and records the resulting provenance locally.

Limit

LaunchZero is not antivirus or EDR and does not vouch for model output. Model-provider traffic, foreign MCP entries, and disclosed direct capabilities remain outside its mediation boundary.