PRIVACY POLICY

N3O for macOS

Jamsoft Inc.

Last Updated: August 12, 2026

Jamsoft Inc. ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how information is handled in N3O (the "App"), our native macOS application for assessing the security of AI systems, Model Context Protocol (MCP) servers, and AI agents.

N3O is professional software that runs entirely on your Mac. We do not operate a server, we do not host an account system, and we have no facility to receive, store, or access your data.

1. Summary

  • We collect no personal information. There are no accounts and no registration.

  • All of your work stays on your Mac, in the App’s sandboxed storage.

  • N3O contains no analytics, telemetry, tracking, or advertising, and no third-party software libraries.

  • N3O makes no network requests on its own. The only outbound traffic is what you explicitly enable and trigger, and it goes to services you choose — never to us.

  • N3O does not use iCloud and does not sync your data anywhere.

2. No Personal Information Collected

We design N3O with your privacy in mind. We do not create user accounts, and we do not collect, store, or have access to any of your personal information. The App functions without requiring you to provide any personal data such as your name, email address, phone number, or location, and it does not gather device identifiers, hardware information, or usage patterns.

If you obtained N3O through the Apple App Store, your purchase and download are handled by Apple under Apple’s own privacy policy. Apple may provide us with anonymous, aggregated sales and performance statistics. We never receive information that identifies you, and we never receive any content you create in the App.

3. Where Your Data Is Stored

N3O stores everything locally on your Mac. Nothing is transmitted to us at any point.

  • Assessment data. Assessments, evidence, system maps, snapshots, findings, threat models, and control catalogs are stored as files in the App’s sandboxed Application Support container.

  • Keys and credentials. Cloud AI provider keys and your deliverable-signing private key are stored in the macOS Keychain. They never leave your Mac and are never written to configuration files in plaintext.

  • Preferences. Settings such as your chosen AI engine and model, and the folder you last saved reports to, are stored in the App’s local preferences. The saved report folder is recorded as a macOS security-scoped bookmark so the destination survives a relaunch.

  • Reports and exports. These are written only to folders you select.

N3O does not use iCloud, CloudKit, or any other synchronisation service. There is no continuous monitoring, no background upload, and no server-side copy of your work.

4. Moving an Assessment Between Macs

N3O can pause an assessment on one Mac and continue it on another. This is done entirely through a file you control — there is no cloud, no account, and no network involved.

The handoff file is encrypted in full using a key derived from a passphrase you set (PBKDF2-HMAC-SHA256 with a random per-file salt), with AES-256-GCM authenticated encryption. Nothing about the assessment, including its name, exists outside the ciphertext. You choose how the file travels — email, external drive, or direct hand-over — and you share the passphrase separately.

Because the passphrase never leaves your possession, Jamsoft cannot read a handoff file, cannot recover a lost passphrase, and cannot restore an assessment on your behalf.

5. Network Activity

N3O initiates no network requests of its own. It does not check for updates over the network, does not phone home, and does not contact us for any reason. There are exactly two circumstances in which the App connects to the internet, and both are started by you.

Optional cloud AI assistance

Off by default and disabled unless you supply your own provider key. This is described in full in Section 6.

Authorisation-gated runtime probes

N3O can run a small, fixed set of diagnostic prompt-injection probes against an AI endpoint during an engagement. This is the only feature that contacts a system being assessed, and it runs only after you record a written client authorisation naming the authorising party, the reference, the scope, the specific hosts, and a time window with an end date.

Every request is checked against that authorisation. An unnamed host, a lapsed window, a redirect away from the authorised host, or credentials in a URL are all refused. Probe traffic goes to the endpoint you named — never to Jamsoft.

All other analysis, including scanning of configuration files, source code, and repositories, is performed on your Mac and is never sent anywhere.

6. Optional Cloud AI (Bring Your Own Key)

By default, N3O’s AI assistance uses Apple Intelligence on-device. Your assessment data does not leave your Mac, and there is no cost.

You may optionally enable a cloud AI tier using your own API key from OpenAI, Anthropic, or Google. If you do:

  • You must enable it in Settings and separately opt in for each individual assessment. It is never enabled automatically.

  • When you request an AI action on an opted-in assessment, the relevant assessment content — which may include control text, your answers, and evidence notes you supplied — is sent directly from your Mac to the provider’s API endpoint using your key.

  • The request goes from your Mac to the provider. Jamsoft does not proxy, receive, log, or store any part of it.

  • Your use of the provider is governed by your own agreement with that provider and by their privacy policy. You are billed directly by them. We are not a party to that relationship.

  • Configuration and source-code scanning is always performed on-device regardless of this setting, because those files routinely contain secrets. Their contents are never sent to a third party.

The providers and endpoints used are OpenAI (api.openai.com), Anthropic (api.anthropic.com), and Google (generativelanguage.googleapis.com). Please review their privacy policies before enabling this feature.

7. Client and Third-Party Information

N3O is professional tooling used to assess systems, often on behalf of a client. In the course of an engagement you may enter information such as client organisation names; the names of assessors, owners, reviewers, and approvers; and evidence describing a client’s systems.

This information is yours. It is stored locally on your Mac and is never transmitted to us. You remain solely responsible for it, including for having the authority to assess the systems you assess, for complying with your own client agreements, and for meeting any legal obligations that apply to the information you handle.

N3O includes safeguards designed to reduce accidental exposure:

  • Imported evidence is checked for provider-shaped credentials and offered for redaction before anything is stored, hashed, previewed, or reported.

  • Runtime probe transcripts pass through the same redaction process automatically.

  • Snapshots record relative paths, content hashes, and masked excerpts rather than copies of your repositories.

  • Credential values discovered during a repository sweep are never copied into the inventory.

  • N3O never executes code supplied to it, and never resolves or contacts addresses found in the artifacts it reads.

These safeguards reduce risk; they do not remove your responsibility for what you put into the App and what you send to a cloud provider you have enabled.

8. No Analytics, Tracking, or Advertising

N3O contains no analytics framework, no telemetry, no crash-reporting service, no advertising, no advertising identifiers, and no user profiling. It includes no third-party software libraries of any kind.

The App’s portfolio view aggregates figures across the assessments stored on your Mac. This is computed locally from your own files, for your own use. It is not an analytics service, it is not transmitted anywhere, and we never see it.

9. Data Retention and Deletion

We retain nothing, because we receive nothing.

You control all retention. You may delete individual assessments within the App at any time. Deleting the App’s Application Support container removes all stored assessments, evidence, snapshots, and catalogs. Keychain items — cloud API keys and your signing key — can be removed from within the App or using the macOS Keychain Access utility. Reports and exports you saved to your own folders are yours to manage; removing the App does not remove them.

10. Security

N3O runs inside the macOS App Sandbox with the minimum entitlements it needs: read and write access to folders you select, the ability to remember those selections, printing, and outbound network access used solely for the features described in Section 5.

Sensitive material is protected using established mechanisms: the macOS Keychain for keys, AES-256-GCM with PBKDF2-derived keys for handoff files, SHA-256 content hashing for evidence integrity, and Ed25519 signatures for deliverable signing.

No method of storage or transmission is completely secure. The security of your assessment data also depends on the security of your Mac, including your use of full-disk encryption, your account password, and the strength of the passphrases you choose for handoff files.

11. Children’s Privacy

N3O is professional security-assessment software intended for business use by adults. It is not directed at, marketed to, or designed for children under the age of 13 (or the equivalent minimum age in the relevant jurisdiction). Because we do not collect personal information of any kind, we do not knowingly collect personal information from children.

12. Your Privacy Rights

Privacy laws such as the GDPR and the CCPA give you rights to access, correct, delete, or port the personal information a company holds about you. Jamsoft Inc. holds no personal information about you, so there is nothing for us to provide, correct, or delete. We do not sell or share personal information, because we never receive any.

The data held by the App is stored on your own Mac and is under your direct control at all times. If you use N3O to process information about other people in the course of an engagement, you act as the controller of that information; Jamsoft has no access to it and does not act as a processor on your behalf.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

14. Contact Us

If you have any questions about this Privacy Policy, please feel free to contact us at:

Jamsoft Inc.

Email: support@jamsoftinc.com