Security architecture

Useful boundaries, explained plainly.

LobeWork is designed with clear boundaries between your local projects, your account, connected providers, and optional features so you can understand what each part can access.

01

Account and access boundary

Sign-in, billing, device authorization, licensing, and organization access are handled separately from your local project folders. Using the customer account portal does not give LobeWork access to the contents of those folders.

02

Voice privacy boundary

Voice is click-to-talk, not always listening. LobeWork does not intentionally store your audio or dictated text as part of ordinary voice use. Availability can depend on the voice option and operating system you choose.

03

Extension boundary

Extensions are expected to declare what they need before use. Permissions and capabilities should be visible so you can make an informed choice before an extension interacts with project resources.

04

Automation boundary

Automation Studio is designed around reviewed actions. LobeWork should not silently perform destructive work, send data, or execute powerful actions without the permissions and confirmations required for that workflow.

05

Local-model boundary

Supported local-model connections are intended to stay local to your computer unless you deliberately configure a remote destination. LobeWork does not turn your local model service into a public endpoint.

06

Support boundary

Support requests do not automatically include your project files. You choose what diagnostics or context to share, and you should never send passwords, provider keys, payment-card details, or unrelated confidential files.

Report a security concern.

Use the dedicated security report form for suspected vulnerabilities, account-security concerns, or unsafe product behavior. Security reports are handled through the private support workflow.

Open security report form