Every commitment, with the place where it is enforced.
As of 4 October 2026 · 10 min read
This page is written for scrutiny, not for first impressions. It is long, tabular and in places uncomfortable. Every commitment comes with the file in which it is enforced — not to sound technical, but so the claim can be checked: a rule that exists only in marketing copy is not a rule.
Local tools and Biwak model access
Local tools work on your computer. For model tasks, your question, the conversation context needed and the file content used are sent via Biwak to the model. Model tasks run signed in, via Biwak, to the model provider in use. Biwak manages the access for your account. Usage is counted against your plan’s allowance.
| Model task | Via Biwak to the model providerThis includes input, the conversation context needed and the file content used. |
|---|---|
| Local tools | Work happens on your computerFile storage and checkpoints stay local; model context is transmitted for processing. |
| Access per account | YesBiwak provides model access for signed-in users and manages the credentials on the server side. |
| Use without an active subscription | Only with the trial creditsNew accounts receive a one-off 100 trial credits; after that, every model task needs an active subscription. |
| Account and billing | Allowances and receiptsBiwak processes account and usage data for access, allowances and billing. |
The local app does not replace a review of the data flows and the agreements required. Take Biwak and the model providers in use into account; data protection, professional secrecy and possible transfers to third countries must be assessed for the specific use case.
Permission levels: four of them, and the boundary isn’t arbitrary
How much Biwak may do on its own is something you choose at the input field, in four levels, before you send a task: “Always ask”, “Read”, “Write” and “Full access”. The default is “Write”. The levels apply to both engines Biwak works with, in the app from version 0.2.27; their current names and their single rule from version 0.2.30: whatever a level allows runs without asking, anything beyond it Biwak puts to you first, and after your yes it happens — the same on every computer. The check sits in the execution path: in the default engine, in its own approval gate and in a Biwak extension that checks every write target before the call; in Biwak’s own loop, before every tool.
| Always ask | Asks before every stepEven before reading. Nothing is remembered at this level — if you mean every step, you mean every step. The file tools write only in the working folder; anything to be changed outside it goes through as a command, and that asks first too. |
|---|---|
| Read | Reads and searches without asking; anything that changes something asks firstWriting files, commands and scripts, sub-agents: Biwak puts each of these to you for approval first, and after your yes it happens. So without your yes, nothing changes. The boundary is your consent, not a technical lock: a command you approve reaches as far as your user account. From version 0.2.30; before that the level was called “Read freely”, and on the Mac the engine ran there in an operating-system sandbox that also refused changes you actually wanted. |
| Write | Reading and files in the working folder without askingWriting, changing and deleting in the working folder go through — the checkpoint covers them. From version 0.2.28, Biwak only changes a file that isn’t in the checkpoint after asking, and the prompt then says explicitly that no undo button will bring it back; older versions leave out files over 12 MB and change them without asking. Anything beyond that — files outside the working folder, commands and scripts — asks first; a command you approve reaches as far as your user account. Before version 0.2.30 the level was called “Files freely”. |
| Full access | Never asksNo prompts: a command reaches the whole computer, and no checkpoint reaches that far. A conscious choice, visible in the interface. Not the default. |
The levels are ordered by effect: first reading, then the files in the working folder, then the whole computer. Each level allows what the previous one allows, and something more. What it doesn’t allow, it doesn’t forbid — it puts it to you: a prompt that holds, instead of a lock that behaves differently from one computer to the next.
The dividing line between “Write” and “Full access” isn’t invented; it already exists in the product: before every task, the checkpoint freezes the working folder. Whatever it can restore — creating, changing, deleting files in the folder — is reversible. Whatever goes beyond that — a command on the whole computer, an entry in a database on a server — is not. That is exactly where the boundary runs.
| Read | Read and search files · web search · fetch pagesChanges nothing. Something still goes out, though: what Biwak reads goes to the model as context, and search and fetch carry search terms and addresses out. Whether Biwak may go online at all is decided by the “Web research” switch in the settings, not by the level. |
|---|---|
| Working folder | Create, change, delete filesCovered by the checkpoint. From version 0.2.28, anything not in it asks first — at every level below “Full access”. |
| Beyond that | Commands and scriptsA command can touch any file your user account can reach, and any computer your network can reach. That’s why it asks first at every level below “Full access”. |
| Unknown tool | Treated as the most far-reachingFail closed. A tool that Biwak’s level check doesn’t know asks first (apps/studio/src/agent/permission.ts). |
And the check sits in the execution path, not in the system prompt. That’s no technicality: in the Replit incident in July 2025, an agent deleted a production database during an explicit code freeze — the freeze existed only in the instructions; nothing in the execution path enforced it.
A database on a server — say, the Oracle database of a law firm’s practice software on the firm’s network — is not protected by any sandbox around files: writes go over a network connection, not into a file on this computer, and no checkpoint restores such an entry. The hard boundary lies in the database itself: a separate database user for Biwak with read-only rights, set up by your IT. Without it, we don’t promise read-only access for a server database. Below “Full access”, every command that wants to connect to it asks first — so you see what happens. Working on a copy of the data avoids touching the live database at all.
What an approval remembers — and why it learns so little
“Allow this command from now on” is the most dangerous spot in an agent tool. Approving shell commands by prefix or pattern is the most CVE-dense pattern in the whole ecosystem, because the shell only splits the command after the check has seen it.
For this one pattern, Claude Code has collected CVE-2025-54795 (viaecho), CVE-2026-24887 (viafind), CVE-2026-25723 (via pipedsed) and CVE-2025-66032 with eight ways through the same read-only list; Cursor CVE-2026-22708 viaexport; Roo Code, Zed, Gemini CLI and Warp each their own.
Biwak has no shell parser and isn’t going to get one. The way out is not to have the problem: only a command without any shell special character is remembered, and it is remembered word for word. No prefix, no pattern, no wildcard. The price is that git status and git status --short are two approvals. That’s the right price. In any case, remembering only happens on “Read” and “Write”; “Always ask” remembers nothing.
- One special character in the command — and it is asked about every time. That includes
^, because it is the escape character on Windows:de^l /s /q C:looks like nothing to a human, and%…%, because cmd.exe substitutes a variable there. - A command that starts a script or a runner —
python3 analyse.py,bun test,make— is never remembered. The wording would stay the same, the file’s content would not: an approval forpython3 analyse.pywould also cover the version the model writes into it a minute later. - An assignment to the environment (
FOO=bar befehl) is not a habit and is not remembered. - Longer than 200 characters: that doesn’t come from a habit but from a script. Not remembered.
- Deletions that take a whole tree with them remain a conscious decision, every time —
rm -rf /,del /s /q,format,Remove-Item -Recurse -Forceand their siblings.
The checkpoint: the whole tent, not just the reported corners
Before a task touches anything, the entire working folder is written to content-addressed storage — and can then be restored exactly as it was.
| Where the storage is | ~/.biwak/safetyOutside the working folder, unless you choose your entire home folder as the working folder. So it can’t clash with your Git, can’t end up in a commit and survives an rm -rf in the folder. |
|---|---|
| What is captured | The whole folder, except .git and node_modulesNot just what a tool reported. A command that moves or deletes files would otherwise be invisible — and that is exactly what nobody can fix by hand afterwards. The two exceptions and the other limits are listed below. |
| Restore | Is itself backed up first“Undo” is not a one-way street. |
| How many checkpoints are kept | 60 per working folder, older states up to 10 GBOlder ones drop out and their objects are cleaned up. If older states take up more than 10 GB — for instance because every task rewrites a large database — the oldest go first; the five most recent checkpoints always stay. |
| Large files | On your computer, no size limitFrom version 0.2.28; older versions leave out files over 12 MB. A large file — a database, a recording, a set of plans — is cloned instead of copied: on the Mac, the backup shares blocks with the original and only takes up space once the original changes; on Windows, it is an ordinary copy. It is read once, to check the content, and after that only when it changes. In the browser workspace, the limit remains 12 MB per file and 400 MB in total. |
| Limits that are reported | 20,000 files · 5 GB kept free · 4 GB of new content per taskIf one of these is reached, the checkpoint says so and gives the reason: “Only part was backed up”, “not enough free space on the drive” or “will be added with the next task”. The same applies to folders nested deeper than 24 levels and to files that can’t be read. Half a checkpoint you know about is usable — one you know nothing about is not. And from version 0.2.28 it has a consequence: Biwak won’t change or delete a file that isn’t in the checkpoint without asking, even on “Write”. |
| Limits that are not reported | .git and node_modulesSkipped without a note in the checkpoint. It’s listed here because it is the difference between “the whole folder” and “almost the whole folder”. |
| What it doesn’t protect against | Effects outside the folderAn email that has been sent, an entry in a database on a server, a file beyond the folder. That’s why commands and scripts ask first below “Full access”. |
Storage: what is on your computer, and in what form
Everything Biwak owns on this machine sits under one folder — so you can back it up, inspect it and delete it in one go. On Windows it is %APPDATA%\biwak, otherwise ~/.biwak.
| Conversations | ~/.biwak/sessions — one JSONL file per conversationAppend-only, in date folders. Plain text: readable with any editor, without us and without any program. |
|---|---|
| Conversation overview | index.jsonl, can be rebuilt at any timeNever maintained by hand. Throwing it away and rebuilding it is allowed — which is why a faster index later on is a file swap, not a migration. |
| Checkpoints | ~/.biwak/safety |
| Log | ~/.biwak/logs — one line of JSON per eventThe tool log is stored locally. Account and usage data for model access are processed separately on the server. |
| Local settings | ~/.biwak/config.jsonOutside the program package. An update replaces the program, not your work. |
| Secrets in the log | The value is replaced, not truncatedFor field names containing key, token, secret, password, authorization, cookie or apikey, «geheim» (secret) appears instead of the content — in the file and on the console. The field name stays visible so you can see that something was there (apps/studio/src/log.ts). |
| Deletion | Deleting the folder is enoughThis line concerns local files. Account and billing data have separate deletion routes and retention periods. |
| Usage data for model tasks | For access and billingUsage is recorded for allowances and billing. The receipts can be viewed in the account. |
Incidentally, the local log is not an extra but evidence that supervisory authorities explicitly want to see — with timestamps for input and output data. It’s just that it stays with you, not with us.
In its AI checklist, the BayLDA requires the use of AI applications “to be logged as evidence of appropriate risk mitigation”.
Network: what the agent is allowed to reach at all
| To the model | Via Biwak model access, not directlyThe task goes to tzvzuholjaulfzgpdeqz.supabase.co (Supabase, Frankfurt am Main) and from there to the model provider. Setting up your own model endpoint is no longer offered. |
|---|---|
| Web search | To a search service, as long as web research is onThe search query leaves the computer. Searching counts as reading and does not ask first from “Read” upwards. Can be switched off with the “Web research” switch in the settings, with allowWeb in the configuration or with BIWAK_ALLOW_WEB=0. For confidential client matters we recommend: off. |
| Fetching pages | Counts as reading, tied to web researchA fetch changes nothing but carries the address out, and does not ask first from “Read” upwards. If web research is off, there is neither search nor fetch. Before every fetch, Biwak’s own loop resolves the host name and rejects anything pointing into the local network (apps/studio/src/agent/web-fetch.ts). |
| Why this check is needed | Otherwise the model reads your own networkA page it is meant to read could send it to http://localhost:4319/api/settings or a router’s web interface — the model doesn’t know which addresses are yours. |
| To us | Model access, account service and update checksA Biwak account is required for model tasks. |
| What your firewall needs to allow | Two for operation, two for the file and updateswww.biwak.ai (sign-in, account, update check), tzvzuholjaulfzgpdeqz.supabase.co (model access), github.com and release-assets.githubusercontent.com (installation file and update packages — the update check itself runs via www.biwak.ai, the package is attached to the release). |
Updates: signed, verified in the Rust core, cannot be switched off
An update channel is the easiest way to slip something into a tool. That’s why the check doesn’t live in the user interface.
| Signature | Ed25519 / minisignVerified before a package can even count as “ready”. Tauri does not allow this check to be switched off. |
|---|---|
| Where the public key lives | In the installed applicationCompiled in, not loaded later (apps/desktop/src-tauri/tauri.conf.json). A package from anywhere else doesn’t match it. |
| What the user interface may do | View status, check, installListed in capabilities/updater.json. From version 0.2.32, a fourth command is added: a request for a silent restart, which the Rust core decides on itself. Download and signature verification stay in the Rust core; direct access to the updater plugin is not enabled. |
| When updates are applied | On quitting, or when you choose “Update”From version 0.2.32: a verified update is applied when you quit Biwak. If the window stays closed for a long time and nothing is running, Biwak restarts silently with the window closed. Biwak never restarts while a task is running; unsent text is saved and restored once afterwards. Older versions only apply an update when you choose “Restart” in the settings. |
| Installation file and update signature | Windows setup with publisher signatureApplies to Windows setup 0.2.30. The setup and every .exe and .dll it installs are signed by “Hermann Hampel”, with a timestamp, via Microsoft’s Azure Artifact Signing. Before uploading, the release run installs the setup and checks every file; if one is unsigned or signed by someone else, nothing is published (scripts/desktop/windows-signierung.ts). Check it yourself: Get-AuthenticodeSignature reports “Valid”. The separate update feed needs at least one package with an update signature and may contain a subset of the platforms; exactly three packages are not required (scripts/desktop/update-manifest.ts). |
| Your data during an update | Stays outside the program packageSessions, configuration and keys survive updates and reinstallation. |
This website
A site that advertises data minimisation while setting three tracking pixels contradicts itself. The verified state of the source code:
| Cookies | Only for signing inThe public pages set none. If you sign in, you get a session cookie — __Host-biwak_sitzung, HttpOnly, Secure, SameSite; without it there would be no sign-in. No analytics, advertising or recognition cookie (packages/konto/src/kern/sitzung.ts). |
|---|---|
| Analytics, statistics, advertising | Anonymous page statisticsVercel Web Analytics counts page views without cookies and without an advertising profile. In addition, existing log files are aggregated without IP address or browser identifier (apps/site/messung.ts). |
| Third-party servers | None when these pages loadNo maps and no social networks; fonts are hosted locally. Vercel delivers the website and the anonymous page statistics. Where sign-in and payment lead is set out in the privacy policy. |
| Stored in the browser | biwak.site.themeOnly whether you chose day or night. No value that recognises you. |
| Forms | One, for requestsEmail address and your choice, sent to our own endpoint — no form service, no embedded calendar, no script from elsewhere (apps/site/vormerken.ts). This page has none, and the form-action header only allows a target where one is needed. |
| Security headers | CSP, HSTS, nosniff, no-referrer, DENYdefault-src 'self'; frame-ancestors 'none'; base-uri 'none'; object-src 'none'. Scripts and styles come from our own origin, inline allowed. The full line is in vercel.json. One exception for framing: only www.biwak.ai itself may embed the chat at /chat/einbettung (frame-ancestors 'self', X-Frame-Options SAMEORIGIN), for the /kontoauszug-umwandeln page. |
| Reporting vulnerabilities | /.well-known/security.txtIn line with RFC 9116, generated at build time rather than stored: in a static file, the mandatory “Expires” field eventually runs out without anyone noticing. Generated, it never expires as long as the site is built. |
| Host | Vercel Inc., USAProcessor under Art. 28 GDPR, standard contractual clauses under Art. 46. Details in the privacy policy. |
Reporting route for security findings: security.txtDOCUMENTS
Is your IT missing a detail? Write to kontakt@biwak.ai — a written reply, no form.REVIEW
Other questions people ask
Can you see what I do with Biwak?
Local tools work on your computer. For model tasks, your question, the conversation context needed and the file content used are sent via Biwak to the model. The local conversation storage must be distinguished from account and usage data and from processing by model providers.
What happens if the agent runs a command I didn’t want?
Below “Full access”, Biwak asks before every command, unless you have already permanently allowed exactly that command (in the app from version 0.2.27, the same on every computer from version 0.2.30). For everything else there’s the checkpoint: before every task it freezes the whole working folder, not just the files a tool reported. Restoring is one button, and the restore is itself backed up first. From version 0.2.28 it also backs up large files on your computer, such as a database, and if it ever has to leave out a file — for instance because there isn’t enough space on the drive — Biwak only changes that file after asking; older versions leave out files over 12 MB. What it doesn’t cover are effects outside the folder — a command on the whole computer, an entry in a database on a server.
Are you certified?
No. We promise neither ISO 27001 certification nor a BSI C5 attestation. Running locally does not, on its own, prove the security of the entire model access.
Do we need a data processing agreement with you?
If you process personal data with Biwak, yes. Our agreement is based on the European Commission’s standard contractual clauses and, for businesses, is part of the terms and conditions, without a separate signature. You can find it at biwak.ai/avv (in German), also as a PDF. Whether your use also touches on matters such as professional secrecy or third-country transfers has to be assessed in the specific case. This page is a description, not a clearance.
How do I verify all this?
Every line on this page comes with the file in which it is enforced. In a demo we open it; on request we send the excerpt in writing, no form. If your IT is missing a detail, write to kontakt@biwak.ai — the reply comes in a form you can pass on.
How can I tell that an update comes from you?
Packages from the built-in updater are verified with the public key built into the installed application. The user interface cannot bypass or switch off this check. This update signature must be distinguished from the installer’s publisher signature: the current Windows setup also carries a Windows publisher signature from “Hermann Hampel”. The download page gives the current version and installation notes.