Topics / Privacy and security

Privacy and security

Inspect release artifacts, local data, CLI provider traffic, Remote access, and optional sharing.

A desktop workspace can keep its own state local while installed model CLIs still contact their providers. Inspect the exact release, decide which integrations to enable, and verify the network and access boundaries in a disposable project. Source code, a digest, and an access PIN each answer a different trust question.

Open this topic's article index for AI assistants →

Guide / 2026-09-28

How do I run Supabase locally with my AI-built app?

Start the Supabase CLI stack, connect the local app to its actual project URL and keys, and verify a test record stays off production.

Read →
Guide / 2026-09-28

How do I test a Trigger.dev email task without emailing real users?

Trace one local signup through the Development worker and a test email destination before an agent runs a side-effecting task.

Read →
Guide / 2026-09-28

Is my local AI-built app using the production database?

Trace the browser, API, worker, and database targets before an agent tests writes or migrations in a locally running app.

Read →
Blog / 2026-09-28

Canopy 0.3.4: test tab recovery, OpenCode usage, and Remote

A task-based reading of the v0.3.4 release notes with a short installed-build trial for closed tabs, OpenCode Statistics, and Remote continuity.

Read →
Guide / 2026-09-28

Can I launch my AI-built app? A founder's decision sheet

A go-or-hold review for an AI-built web app: running behavior, access, data, payments, recovery, and the exact release version.

Read →
Guide / 2026-09-28

Review an AI-generated Supabase migration before deployment

Check the target project, schema diff, existing data, RLS, staging result, and actual restore option before an agent-written migration reaches production.

Read →
Guide / 2026-09-28

My coding agent committed an API key. What now?

A staged response to an agent-written secret leak: stop propagation, revoke the credential, restore services, inspect exposure, and decide whether Git history needs cleanup.

Read →
Guide / 2026-09-28

Review an AI-built Stripe Checkout before taking payments

A founder's test-mode review of Checkout, signed webhooks, delayed payments, duplicate events, and fulfillment before launch.

Read →
Guide / 2026-09-28

How to review an AI-generated access-control PR

Use a permission matrix and cross-user tests to review an agent-written authentication or authorization change before merge.

Read →
Guide / 2026-09-28

Why does my coding agent keep asking for permission?

Diagnose repeated coding-agent approval prompts by checking the action, CLI rules, working directory, and session before changing permissions.

Read →
Guide / 2026-09-28

MCP server configured but unavailable to your coding agent?

Diagnose MCP scope, connection, authentication, tool selection, and cross-CLI setup with a read-only documentation server as the example.

Read →
Guide / 2026-09-28

How to inspect an open-source AI IDE before installing it

A repeatable Canopy release check: match installer to tag, verify the asset digest, read source and license boundaries, and test what connects to the network.

Read →
Use case / 2026-09-28

Who can control your coding agent through Canopy Remote?

Understand the PIN, running-host requirement, tunnel, scoped Remote commands, and why terminal access still deserves care.

Read →
Use case / 2026-09-28

What leaves your machine when you use Canopy?

A plain-language map of local workspace data, coding CLI traffic, optional GitHub and team services, remote tunnels, and on-device dictation.

Read →
Use case / 2026-09-28

Share agent work with a team without sharing AI accounts

A host, implementer, and reviewer handoff through Canopy Team: project chat, files, review requests, disk ownership, and separate model accounts.

Read →
Use case / 2026-09-27

Resume a local coding agent from your phone

Use Canopy Remote to inspect a running project, reconnect after a phone disconnect, and steer the right agent without repeating a task.

Read →
Guide / 2026-09-28

Review a coding-agent skill before your team shares it

Inspect a borrowed SKILL.md, its scripts, tool access, and test behavior before making a repeatable workflow available to every agent.

Read →
Use case / 2026-09-28

Can Canopy work offline with a local coding agent?

Test local files, Git, services, Preview, search, and a preinstalled CLI against the separate requirement for a local model endpoint.

Read →
Use case / 2026-09-28

Canopy Remote, Claude Code, Copilot CLI, or SSH from your phone?

Choose a remote coding-agent workflow by host state, CLI coverage, project evidence, access rules, and what you can actually verify on a phone.

Read →
Guide / 2026-09-28

Run OpenCode with a local Ollama model in Canopy

Set up a local model route, account for OpenCode V1 and V2 differences, verify context and tool use, then test an offline coding task in Canopy.

Read →