Current evidence
LaunchZero is local-first, with no LaunchZero cloud in the enforcement path. Keys managed through LaunchZero live in its local encrypted store; provider credentials remain within the agent's configured trust boundary.
A gateway that guards your agent should not ask for blind trust. This ledger separates what LaunchZero claims, what you can inspect now, and where the boundary stops.
LaunchZero's policy, Activity, and managed secret store stay on your machine.
Current evidence
LaunchZero is local-first, with no LaunchZero cloud in the enforcement path. Keys managed through LaunchZero live in its local encrypted store; provider credentials remain within the agent's configured trust boundary.
Limit
LaunchZero cannot make a fully compromised operating system safe.
The gateway guarding the agent is itself open to inspection.
Current evidence
The complete local-first gateway source is public under AGPL-3.0.
Limit
Public source makes review possible; it does not replace your own evaluation.
The organization responsible for LaunchZero is named and reachable.
Current evidence
LaunchZero is a Security Research Group product.
Inspect or verify
Learn about Security Research GroupLimit
LaunchZero remains the product; the maker relationship is supporting evidence.
Published artifacts inherit their status from the release source of truth.
Current evidence
Release 2026.07.25 · is the current data-driven build. A checksum manifest and detached signature are published.
Limit
Release claims follow the fields and capability flags in the release source of truth; no additional signing or build guarantees are implied.
Good-faith security reports have a direct destination.
Current evidence
Send the issue, impact, and clear reproduction steps to the dedicated disclosure address.
Limit
No response-time or remediation-time commitment is asserted here.
LaunchZero governs mediated requests; it does not claim to solve every host risk.
Current evidence
It policy-gates monitored tools and managed integrations, including file and network access through those governed paths, and records the resulting provenance locally.
Limit
LaunchZero is not antivirus or EDR and does not vouch for model output. Model-provider traffic, foreign MCP entries, and disclosed direct capabilities remain outside its mediation boundary.