SECURITY

Your sessions hold your secrets. Here is how Postrun keeps them.

Agent sessions contain full prompts, tool output and anything a command printed. Postrun records them on your own machine and shares nothing unless you export a session yourself.

~/.postrunEvery session is stored on your machine, in folders set to 0700 and files set to 0600.
127.0.0.1Both listeners bind to loopback only and refuse requests with any other Host header.
no telemetryThe app never contacts our servers. There is no analytics or crash reporting in it.
Bearer tokenThe one write route, POST /api/ingest, needs a token stored in an owner-only file.
[REDACTED:kind]Exports mask secrets, credentials and home paths, and list every masked value.
default-src 'none'Exported reports contain no JavaScript, and their CSP blocks scripts and network requests.

Local by default. Shared on purpose.

Postrun is in early access for Claude Code and Cline. Open the example report to see exactly what an export looks like, or join the waitlist for the install.