LocalCloud security
Check what you install before you run it, keep your data on your machine, and reach us privately when you find a problem.
Report a vulnerability
Email info@local.cloud with the subject "Security report". Include the affected part (CLI, runtime image or website), its version (localcloud --version or the image digest), the steps to reproduce it, and the impact you observed.
Please don't include real credentials or customer data, and test only against systems you own. Our security.txt lists the same contact in the standard format.
Signed CLI releases
Every CLI release publishes archives for macOS and Linux on amd64 and arm64, a SHA256SUMS file, and Sigstore bundles. The bundles are signed by the CLI's GitHub Actions release workflow, so cosign can confirm the files came from that workflow at a release tag. The install script checks each archive against SHA256SUMS before it installs anything.
Check the signature on the v0.1.7 checksums
curl -fsSLO https://github.com/LocalGCloud/localcloud-cli/releases/download/v0.1.7/SHA256SUMS
curl -fsSLO https://github.com/LocalGCloud/localcloud-cli/releases/download/v0.1.7/SHA256SUMS.sigstore.json
cosign verify-blob SHA256SUMS \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity-regexp '^https://github\.com/LocalGCloud/localcloud-cli/\.github/workflows/cli-release\.yml@refs/tags/v' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com Then check a downloaded archive against them
sha256sum --check --ignore-missing SHA256SUMS On older macOS versions, use shasum -a 256 --check --ignore-missing SHA256SUMS. Release history is on the changelog.
Runtime image SBOM and provenance
The agentcloud/localcloud image is published for linux/amd64 and linux/arm64. Each platform carries an SPDX software bill of materials and a SLSA build provenance attestation. Inspect them with Docker:
Software bill of materials (SPDX)
docker buildx imagetools inspect agentcloud/localcloud:latest --format '{{ json .SBOM }}' Build provenance (SLSA)
docker buildx imagetools inspect agentcloud/localcloud:latest --format '{{ json .Provenance }}' For repeatable CI runs, pin the image by digest rather than the latest tag.
Your data and telemetry
Service data stays in a Docker volume on your machine (localcloud-data by default), and the quick start runs LocalCloud on localhost-only ports. LocalCloud needs no Google Cloud account or credentials.
The runtime sends pseudonymous usage and diagnostic reports. Set LOCALCLOUD_TELEMETRY=false in the container's environment to stop regular reporting. The privacy notice lists what is sent and what else can make network requests.