Local-first data
Local paths, logs, conversation histories, usage records, credentials, and raw runtime data are designed to remain on the device in default client scenarios.
Security & privacy
LicoUp’s security model separates user-controlled endpoint authority from transport infrastructure. Stations are treated as untrusted transport, not as a source of identity, plaintext, keys, approval, or final trust decisions.
Local paths, logs, conversation histories, usage records, credentials, and raw runtime data are designed to remain on the device in default client scenarios.
LicoUp owns endpoint private-key custody and uses platform secure storage where available, with explicit memory-only fallback boundaries where documented.
External operations require fresh direct approval bound to destination, purpose, scope, and content. Prior installation or agent intent is not treated as permanent authorization.
A station response, timestamp, acknowledgement, queue state, or delivery claim is only an operational hint. Endpoint authentication and acceptance remain endpoint decisions.
Peer transfer today
The current Secure Client Mesh source contains a client-specific preview path for pairing, authenticated encryption, freshness and replay handling, and endpoint-authenticated results. The sender encrypts approved peer content before network I/O; the station is not intended to receive plaintext or endpoint keys.
This preview is not a Lico Arc Profile and carries no future interoperability promise. It is scheduled for direct retirement when a complete pinned Lico Arc Protocol Line is available.
The distinction matters: cryptographic construction and protocol governance should be claimed only from the authority that actually owns them.
External services
Transport protection does not make an approved external service blind to content deliberately sent to it. A protected peer-endpoint transfer is distinct from an external service request.
For example, if a user explicitly enables Telegram as a communication channel, content sent through Telegram remains readable by Telegram. LicoUp treats that as an admitted external channel rather than pretending it inherits peer-endpoint privacy semantics.
Security evidence