security & privacy
Triss sits between an agent, your filesystem, and your credentials.
This page is the short version for a vendor security review. SECURITY.md is the normative document.
no telemetry
zero data to the developers
local-first
CLI, not hosted service
7 deps
plain ESM, no build
MIT
auditable on GitHub
01 — outbound traffic
Three default destinations — plus any URL you ask Triss to fetch.
you configure it
The model endpoint
Prompts and the selected corpus go to the OpenAI-compatible endpoint you set.
TRISS_WORKER_BASE_URL
you configure it
Your trackers
Tracker commands talk to the Jira/Linear/GitHub instance you configured — only when a credential exists.
per-integration env vars
carries nothing
Update discovery
A credential-free GET to a fixed public Release endpoint when the cache is due.
TRISS_UPDATE_CHECK=0
