declass.

A terminal coding agent for confidential work

Frontier AI coding.
Private context
stays local.

Declass is a terminal coding agent where the cloud model never sees your sensitive data. The cloud model writes the code, and a local model on your machine reads that data and answers its questions.

Most coding agents send everything they read to the cloud, including .env files, customer data, and logs. With Declass, when the cloud model needs something from your sensitive data, it has to ask the local model. Declass checks every answer before it leaves, so secrets and raw data stay put.

It still does everything you'd expect from a coding agent, from editing files to running tests to working through tasks end to end. It just does it without handing over the parts of your codebase you can't afford to share.

Running everything locally would avoid sending anything, but local models are still well behind the best cloud models at writing code. Declass gives you the cloud model's coding and keeps the private context on your machine, with a record of exactly what was sent.

A real session on fictional customer data. The bug is fixed, the tests pass, and none of the 13 planted secrets appear in the 5 requests sent to the cloud. Agent work plays at 6× speed. Recording and evidence
01

Ordinary code goes to the cloud model as it is.

Files that match your sensitive patterns (by default .env*, keys, data/**, CSVs, databases and logs) are not. The cloud model gets their structure (column names, value types, synthetic example rows) and can ask your local model specific questions about them.

02

Everything that goes out is checked.

Including the local model's answers, against the private values Declass has seen. Secrets and personal data are replaced with placeholders such as ⟨secret:URL_PASSWORD#1⟩. The local model can't approve its own answers.

03

Commands run in a sandbox.

Seatbelt on macOS, bubblewrap on Linux, with network access limited to package registries.

04

You can inspect every request.

The Changes panel shows the diff. The Privacy panel shows each request and what was filtered from it. declass audit show <run> prints the full log, which is hash-chained so you can check it hasn't been altered.

This doesn't make leaks impossible. Declass blocks known private values, and the local model also checks its answers for paraphrased details, but that check is a model's judgement, and an answer like “3 customers are overdue” still goes out by design. What is and isn't covered

89.3% of hidden tests passed with Declass 96.5% for the same model with no protection
0 planted secrets found in 1,124 Declass requests 35,809 found in 1,328 unprotected requests

Nine coding tasks, each with planted private data (customer records, credentials, logs, proprietary pricing), run three times with Declass and three times without. Most of the gap comes from two Declass runs that scored zero, both counted. The tasks are mine, it's one cloud model, and three runs per task is a small sample. Method and full evidence

macOS and Linux, on ARM64 or x86-64:

curl -fsSL https://raw.githubusercontent.com/maximpri/declass/main/install.sh | bash

Then, in your project:

declass

The first time, a setup screen shows the API keys in your environment and the model servers on your machine. You choose the cloud model and the local model, review who receives what, and save. Declass has no default models and sends nothing until you choose.

No API key? A ChatGPT Plus or Pro plan works instead:

declass login chatgpt

No sudo or Rust toolchain needed. Releases are signed with the Declass release key. Installation guide · Usage guide

↗

Cloud

Anthropic, OpenAI, Google Gemini, OpenRouter, z.ai, DeepSeek, xAI, Mistral, Groq, Cerebras, Together, Fireworks and Qwen, or any OpenAI-compatible endpoint. Or a ChatGPT Plus or Pro plan, with no API key.

↙

Local

Ollama, LM Studio, llama.cpp, vLLM, oMLX, MLX, Jan, GPT4All, KoboldCpp, LocalAI and LiteLLM. It needs a context window of about 40K tokens. It only reads and answers questions, so it doesn't need to be good at coding.

Built for teams working with financial records, confidential systems and proprietary code.

Download the latest release
GPL-3.0-or-later.