# LocalCloud security

> Verify signed LocalCloud CLI releases and the runtime image's SBOM and provenance, see where your data stays, and report a vulnerability.
>
> Source: https://local.cloud/security/

Security

Check what you install before you run it, keep your data on your machine, and reach us privately when you find a problem.

[Report a vulnerability](mailto:info@local.cloud?subject=Security%20report) [security.txt](https://local.cloud/.well-known/security.txt)

## Report a vulnerability

Email [info@local.cloud](mailto:info@local.cloud?subject=Security%20report) with the subject "Security report". Include the affected part (CLI, runtime image or website), its version (`localcloud --version` or the image digest), the steps to reproduce it, and the impact you observed.

Please don't include real credentials or customer data, and test only against systems you own. Our [security.txt](https://local.cloud/.well-known/security.txt) lists the same contact in the standard format.

## Signed CLI releases

Every [CLI release](https://github.com/LocalGCloud/localcloud-cli/releases) publishes archives for macOS and Linux on amd64 and arm64, a `SHA256SUMS` file, and Sigstore bundles. The bundles are signed by the CLI's GitHub Actions release workflow, so cosign can confirm the files came from that workflow at a release tag. The install script checks each archive against `SHA256SUMS` before it installs anything.

### Check the signature on the v0.1.7 checksums

```
curl -fsSLO https://github.com/LocalGCloud/localcloud-cli/releases/download/v0.1.7/SHA256SUMS
curl -fsSLO https://github.com/LocalGCloud/localcloud-cli/releases/download/v0.1.7/SHA256SUMS.sigstore.json
cosign verify-blob SHA256SUMS \
  --bundle SHA256SUMS.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/LocalGCloud/localcloud-cli/\.github/workflows/cli-release\.yml@refs/tags/v' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
```

### Then check a downloaded archive against them

```
sha256sum --check --ignore-missing SHA256SUMS
```

On older macOS versions, use `shasum -a 256 --check --ignore-missing SHA256SUMS`. Release history is on the [changelog](https://local.cloud/changelog/).

## Runtime image SBOM and provenance

The [`agentcloud/localcloud`](https://hub.docker.com/r/agentcloud/localcloud) image is published for linux/amd64 and linux/arm64. Each platform carries an SPDX software bill of materials and a SLSA build provenance attestation. Inspect them with Docker:

### Software bill of materials (SPDX)

```
docker buildx imagetools inspect agentcloud/localcloud:latest --format '{{ json .SBOM }}'
```

### Build provenance (SLSA)

```
docker buildx imagetools inspect agentcloud/localcloud:latest --format '{{ json .Provenance }}'
```

For repeatable CI runs, pin the image by digest rather than the `latest` tag.

## Your data and telemetry

Service data stays in a Docker volume on your machine (`localcloud-data` by default), and the quick start runs LocalCloud on localhost-only ports. LocalCloud needs no Google Cloud account or credentials.

The runtime sends pseudonymous usage and diagnostic reports. Set `LOCALCLOUD_TELEMETRY=false` in the container's environment to stop regular reporting. The [privacy notice](https://local.cloud/docs/privacy/) lists what is sent and what else can make network requests.
