Declass is a terminal coding agent where the cloud model never
sees your sensitive data. The cloud model writes the code, and a
local model on your machine reads that data and answers its
questions.
Most coding agents send everything they read to the cloud,
including .env files, customer data, and logs. With
Declass, when the cloud model needs something from your sensitive
data, it has to ask the local model. Declass checks every answer
before it leaves, so secrets and raw data stay put.
It still does everything you'd expect from a coding agent, from
editing files to running tests to working through tasks end to
end. It just does it without handing over the parts of your
codebase you can't afford to share.
Running everything locally would avoid sending anything, but
local models are still well behind the best cloud models at
writing code. Declass gives you the cloud model's coding and
keeps the private context on your machine, with a record of
exactly what was sent.
A real session on fictional customer data. The bug is fixed, the
tests pass, and none of the 13 planted secrets appear in the 5
requests sent to the cloud. Agent work plays at 6× speed.
Recording and evidence
02 / How it works
Two models. One boundary.
The mark is a split D: the upright is your machine and its local
model, the bowl is the cloud model, and the gap between them is
where Declass checks what crosses.
01
Ordinary code goes to the cloud model as it is.
Files that match your sensitive patterns (by default
.env*, keys, data/**, CSVs,
databases and logs) are not. The cloud model gets their
structure (column names, value types, synthetic example rows)
and can ask your local model specific questions about them.
02
Everything that goes out is checked.
Including the local model's answers, against the private
values Declass has seen. Secrets and personal data are
replaced with placeholders such as
⟨secret:URL_PASSWORD#1⟩. The local model can't
approve its own answers.
03
Commands run in a sandbox.
Seatbelt on macOS, bubblewrap on Linux, with network access
limited to package registries.
04
You can inspect every request.
The Changes panel shows the diff. The Privacy panel shows each
request and what was filtered from it.
declass audit show <run> prints the full
log, which is hash-chained so you can check it hasn't been
altered.
This doesn't make leaks impossible. Declass blocks known private
values, and the local model also checks its answers for
paraphrased details, but that check is a model's judgement, and
an answer like “3 customers are overdue” still goes out by design.
What is and isn't covered
03 / Results
Nearly the same code. None of the secrets.
89.3%of hidden tests passed with Declass96.5% for the same model with no protection
0planted secrets found in 1,124 Declass requests35,809 found in 1,328 unprotected requests
Nine coding tasks, each with planted private data (customer
records, credentials, logs, proprietary pricing), run three times
with Declass and three times without. Most of the gap comes from
two Declass runs that scored zero, both counted. The tasks are
mine, it's one cloud model, and three runs per task is a small
sample.
Method and full evidence
The first time, a setup screen shows the API keys in your
environment and the model servers on your machine. You choose the
cloud model and the local model, review who receives what, and
save. Declass has no default models and sends nothing until you
choose.
No API key? A ChatGPT Plus or Pro plan works instead:
declass login chatgpt
No sudo or Rust toolchain needed. Releases are signed
with the Declass release key.
Installation guide
·
Usage guide
05 / Models
Bring your own two models.
↗
Cloud
Anthropic, OpenAI, Google Gemini, OpenRouter, z.ai, DeepSeek,
xAI, Mistral, Groq, Cerebras, Together, Fireworks and Qwen, or
any OpenAI-compatible endpoint. Or a ChatGPT Plus or Pro plan,
with no API key.
↙
Local
Ollama, LM Studio, llama.cpp, vLLM, oMLX, MLX, Jan, GPT4All,
KoboldCpp, LocalAI and LiteLLM. It needs a context window of
about 40K tokens. It only reads and answers questions, so it
doesn't need to be good at coding.
Built for teams working with financial records, confidential systems
and proprietary code.