# Privacy and security — Canopy > Inspect release artifacts, local data, CLI provider traffic, Remote access, and optional sharing. A desktop workspace can keep its own state local while installed model CLIs still contact their providers. Inspect the exact release, decide which integrations to enable, and verify the network and access boundaries in a disposable project. Source code, a digest, and an access PIN each answer a different trust question. Canopy runs installed coding CLIs; their providers control model access, limits, and billing. Check the installed app release for version-specific features. Each link opens the article's clean Markdown version. ## Articles - [Can Canopy work offline with a local coding agent?](https://canopyide.dev/use-cases/canopy-offline-local-coding-agent-workflow.md): Test local files, Git, services, Preview, search, and a preinstalled CLI against the separate requirement for a local model endpoint. - [Can I launch my AI-built app? A founder's decision sheet](https://canopyide.dev/guides/ai-built-app-launch-checklist-for-founders.md): A go-or-hold review for an AI-built web app: running behavior, access, data, payments, recovery, and the exact release version. - [Canopy 0.3.4: test tab recovery, OpenCode usage, and Remote](https://canopyide.dev/blog/canopy-034-agent-workflow-release-guide.md): A task-based reading of the v0.3.4 release notes with a short installed-build trial for closed tabs, OpenCode Statistics, and Remote continuity. - [Canopy Remote, Claude Code, Copilot CLI, or SSH from your phone?](https://canopyide.dev/use-cases/canopy-remote-vs-claude-code-copilot-ssh.md): Choose a remote coding-agent workflow by host state, CLI coverage, project evidence, access rules, and what you can actually verify on a phone. - [How do I run Supabase locally with my AI-built app?](https://canopyide.dev/guides/run-supabase-locally-with-ai-built-app.md): Start the Supabase CLI stack, connect the local app to its actual project URL and keys, and verify a test record stays off production. - [How do I test a Trigger.dev email task without emailing real users?](https://canopyide.dev/guides/test-trigger-dev-email-task-without-real-users.md): Trace one local signup through the Development worker and a test email destination before an agent runs a side-effecting task. - [How to inspect an open-source AI IDE before installing it](https://canopyide.dev/guides/inspect-open-source-ai-ide-before-installing.md): A repeatable Canopy release check: match installer to tag, verify the asset digest, read source and license boundaries, and test what connects to the network. - [How to review an AI-generated access-control PR](https://canopyide.dev/guides/review-ai-generated-access-control-pr.md): Use a permission matrix and cross-user tests to review an agent-written authentication or authorization change before merge. - [Is my local AI-built app using the production database?](https://canopyide.dev/guides/is-local-ai-built-app-using-production-database.md): Trace the browser, API, worker, and database targets before an agent tests writes or migrations in a locally running app. - [MCP server configured but unavailable to your coding agent?](https://canopyide.dev/guides/mcp-server-not-available-to-coding-agent.md): Diagnose MCP scope, connection, authentication, tool selection, and cross-CLI setup with a read-only documentation server as the example. - [My coding agent committed an API key. What now?](https://canopyide.dev/guides/coding-agent-committed-api-key-to-github.md): A staged response to an agent-written secret leak: stop propagation, revoke the credential, restore services, inspect exposure, and decide whether Git history needs cleanup. - [Resume a local coding agent from your phone](https://canopyide.dev/use-cases/resume-coding-agent-from-phone.md): Use Canopy Remote to inspect a running project, reconnect after a phone disconnect, and steer the right agent without repeating a task. - [Review a coding-agent skill before your team shares it](https://canopyide.dev/guides/review-coding-agent-skill-before-sharing.md): Inspect a borrowed SKILL.md, its scripts, tool access, and test behavior before making a repeatable workflow available to every agent. - [Review an AI-built Stripe Checkout before taking payments](https://canopyide.dev/guides/review-ai-built-stripe-checkout-before-launch.md): A founder's test-mode review of Checkout, signed webhooks, delayed payments, duplicate events, and fulfillment before launch. - [Review an AI-generated Supabase migration before deployment](https://canopyide.dev/guides/review-ai-generated-supabase-migration-before-deploy.md): Check the target project, schema diff, existing data, RLS, staging result, and actual restore option before an agent-written migration reaches production. - [Run OpenCode with a local Ollama model in Canopy](https://canopyide.dev/guides/opencode-ollama-local-model-in-canopy.md): Set up a local model route, account for OpenCode V1 and V2 differences, verify context and tool use, then test an offline coding task in Canopy. - [Share agent work with a team without sharing AI accounts](https://canopyide.dev/use-cases/share-agent-work-with-a-team.md): A host, implementer, and reviewer handoff through Canopy Team: project chat, files, review requests, disk ownership, and separate model accounts. - [What leaves your machine when you use Canopy?](https://canopyide.dev/use-cases/what-leaves-your-machine-when-using-canopy.md): A plain-language map of local workspace data, coding CLI traffic, optional GitHub and team services, remote tunnels, and on-device dictation. - [Who can control your coding agent through Canopy Remote?](https://canopyide.dev/use-cases/who-can-control-agent-through-canopy-remote.md): Understand the PIN, running-host requirement, tunnel, scoped Remote commands, and why terminal access still deserves care. - [Why does my coding agent keep asking for permission?](https://canopyide.dev/guides/coding-agent-keeps-asking-permission.md): Diagnose repeated coding-agent approval prompts by checking the action, CLI rules, working directory, and session before changing permissions.