Skip to content

Security & Privacy

  • Local First: Cluster credentials and configuration never leave your device and are never sent to Kubeterm servers. All API calls go directly from your device to the Kubernetes API.
  • Secure Credential Storage: AI provider API keys and cluster credentials are stored in platform secure storage (Keychain on Apple, credential store on Windows). On Linux and Windows, this can be toggled to use the system credential store or local encrypted storage.
  • iCloud Sync: On Apple devices, cluster configurations and AI provider settings can be synced across your devices using iCloud Keychain.
  • Biometric Lock: Require Touch ID or Face ID before accessing a specific cluster or before applying any write operation. Configured per cluster.
  • Per-Cluster Proxy: Route cluster traffic through a different proxy than the global default — useful in environments with network segmentation.
  • AI Tool Policy: Explicitly control which operations the AI assistant is permitted to run against the cluster API. Default is read-only.