Skip to content
Stewards Stewards
  • Home
  • Privacy Policy
  • Terms of Use
  • How Processing Works
  • Security & Risk Disclosure
  • Sign in

Stewards

Security & Risk Disclosure

The same text Stewards shows under Settings › About. Revised 16 September 2026.

This document describes what Stewards does with your data, what it does not protect against, and which decisions remain yours. It is written to be relied on, so it states limits plainly rather than favorably. If a sentence here ever stops matching the software, the sentence is the defect.

1. THE CORE PROMISE

Stewards stores none of your work on its servers.

Your Matters, notes, files, and conversations live on your device and nowhere else. There is no server-side copy, no cloud sync, and no server-side chat history. The gateway itself runs on a rented virtual server (Aleph Cloud); the Privacy Policy lists what it holds, and a sealed request reaches it as ciphertext it cannot open. AI requests are processed transiently — Stewards' servers keep no copy of your prompts, responses, or search queries — and your work is never used by Stewards to train AI models. When account sign-in is enabled, the service keeps an opaque account identifier and the sign-in subject assigned by Auth0 — the identity service behind every sign-in method, including Apple and Google, which receives your email or sign-in account and keeps its own records — plus sign-in sessions, any passkeys you have added, invitation and access dates, the payment processor's reference when a card is on file, daily and monthly request counts, and aggregate input and output token counts by model and allowance period. These records describe access and usage, never what you wrote. The account database stores no password, payment-card details, or email address; an invitation keeps only a keyed fingerprint of the address it was sent to, and a passkey record keeps only its public key — the private key stays on your device. The operator can link an account to its sign-in identity; no one else can. Records are kept while the account exists, and you can delete the account yourself from Settings › Usage & Account or from the account page, which removes them in one step.

Stewards watches itself, not you.

The app contains no analytics, no crash reporting, and no behavioral tracking. Settings › Data Activity keeps a local record of every request that carries your work — every AI request, drafted query, approved search, and fetched page — so you can verify what left this device; that log never leaves it. Four kinds of request carry no work and are not in the log: the Mac app's update check (which you can turn off in Settings › Software Updates), a question at launch whether the gateway requires an account, verification checks when you open a Matter or Protections without a current reading and before every AI query, web search, and page fetch, and the allowance lookup when you open Usage & Account. Each reveals your network address, the app version, and your system language to the server it reaches, and all but the update check also reveal your version of macOS. An update download also presents your update credential. The allowance lookup presents your sign-in session, and the confidential-compute question may present it too. None of them reveals anything else.

Your files carry the risk they always had — and a little less.

The work you keep in Stewards sits on your own computer, with the same exposure as the folder you dragged each file in from. On top of that, Stewards encrypts the substance — note bodies, message contents, extracted document text, summaries, your glossary, the party each Matter says it represents, your writing samples and style notes, imported file blobs, and the pointer back to where each file was imported from — with a device-bound key held in your device's Keychain: it never syncs, and it never moves to another machine. That is defense in depth, not a claim that your own computer is the threat. Titles, filenames, and timestamps are not encrypted; see section 2.

Protection levels control what leaves.

Each Matter carries a level that governs egress:

  • Standard — the Matter title, included notes, and included file excerpts accompany AI requests; the party you represent accompanies requests made from the discovery drafter; and a writing style you apply to the Matter — passages chosen on this device from your own writing samples, scrubbed here as they were added, with measurements and your notes — accompanies chat and drafting requests. Web research is available: detected identifying terms in a search query are shown to you as advisory warnings, and the Matter can send its search queries without the scrub.
  • Guarded — the default. The same AI context as Standard. In both levels, titles and file names are scrubbed before chat, search-query drafting, and document-tool requests — glossary terms, the party you represent, and detected identifiers become labels; note bodies and file excerpts still go as written, and an applied writing style's passages go as you saved them — the separately configured represented-party line still names the party in discovery drafting. A web search is blocked outright while a glossary term, the party you represent, or a structured identifier remains in the query; other names Stewards detects are flagged for you to check, not blocked.
  • Local-Only — the Matter's title, notes, files, the party you represent, its trusted-sources pack's jurisdiction, any writing style it applied, and the research block from any earlier search (its query and result snippets) are never included in AI requests, web research is impossible, and the activity log does not name the Matter. The research block stops accompanying requests the moment you set the level, and the conversation's earlier turns stop with it: when you raise a Matter's protection, turns from before the change stay on this device — your messages, the assistant's answers, and any "Read source" lines among them — and turns after it accompany chat requests as before.

You approve what reaches the public web.

Stewards never searches the web on its own. The AI writes a query — when you start a search, or in its reply when it suggests one — from your words and the Matter context that accompanies chat; a lookup of an authority the citation check flagged starts from that authority's own words instead, scoped to the Matter's trusted source for it. On this device Stewards then removes your glossary terms, the party you represent, and structured identifiers — email addresses, phone, ID, account and docket numbers, street addresses, and dates — unless a Standard Matter has turned that off, and flags the other names it detects without removing them, because name recognition cannot tell a client from a case name or a court. It shows you exactly what it removed and flagged and which details from the Matter the query uses, each of which you can put in or take out, and lets you edit the text. What you approve is what is sent, unmodified: sealed on this device to Tinfoil's search enclave once its hardware, encryption key, and signed build pass the checks described in (d) below, so the gateway relays it unread. Inside the enclave, Tinfoil's search service runs it on Exa, a search engine, which sees the approved query but never your network address or the gateway's. Your notes, files, and messages are never sent to search.

Retrieved material is treated as evidence, not instruction.

Web pages and file excerpts are wrapped in labeled boundaries so text inside them cannot pose as a command to the AI. This defends against a document or web page that tries to hijack the assistant.

2. LIMITS AND RISKS

Grouped by where the risk actually lives. None of them are hypothetical.

WHAT LEAVES THE DEVICE

a. What you type in chat is sent as written.

Stewards offers — and never applies on its own — a substitution when your glossary terms, the party you represent, or a structured identifier (an email address, phone number, ID or account number, docket number, or street address) appears in a draft message or drafting instruction; Message Check in Settings turns the offer off, and "Send as Written" is always one click away. Names are not part of that check — the glossary is how you say which names matter. Beyond that offer, anything you type into a message, and the text of any file you include in Matter context, is transmitted as written; the passages of a writing style you apply are transmitted as you saved them after this device's scrub, and they are never checked against a Matter's glossary. Sending a message always transmits that message and recent conversation history for AI processing, at every protection level. That is the product working, not a defect — but it means the redaction system is not a safety net for what you type. Open What’s Shared — the strip’s Request context cell, or the conversation menu on iPhone and iPad — to see and edit exactly what accompanies requests, and Show request beneath the composer to read the request itself, every message in order, before you send it. Discovery drafting transmits your coverage instructions the same way, at every protection level; suggesting topics and drafting responses to an incoming set transmit this Matter's context and, for responses, that file's request text, and neither is available in Local-Only Matters.

b. Web research involves the AI before you approve anything.

The AI writes each search query from your words and the Matter context that accompanies chat — the approval card governs what reaches the search engine, not what reaches the AI. A query can carry a detail from that context that no pattern recognizes, and names Stewards detects are flagged rather than removed: the glossary is how a name is kept out of a search. Once a search runs, its query and result snippets accompany later messages in that conversation as a research block, withheld once the Matter is Local-Only; the question and the assistant's answers are ordinary conversation history and ride along at every level until you raise the Matter's protection: turns from before the change stay on this device, and turns after it accompany chat requests as before. And opening a search result, a cited source, or a linked authority opens it in your browser: your device connects directly to that site, outside Stewards.

c. Some decisions are deliberately yours.

Stewards warns, and under Guarded it blocks — but approving an edited query, researching before you lock the level down, or sharing an original file are choices the software will not overrule. It makes those moments visible; the judgment is yours. If work is sensitive, make it Local-Only before you research or chat about it, not after.

THE AI SERVICE

d. Confidential compute: what the check proves, and what it still cannot.

Stewards processes AI requests inside trusted execution environments (TEEs) with remote attestation — hardware-sealed processing that even the operator cannot read — and every Matter’s strip reads how far that is proven right now. Stewards sends AI requests only after verifying the enclave's hardware, encryption key, and signed software build on this device. The app fetches the enclave's attestation and, separately, the enclave's own key configuration through the Stewards Gateway; it verifies the AMD SEV-SNP report on this device against AMD root certificates pinned in the app — the signature chain, the report signature, that guest debugging is off — and checks that the key it is about to encrypt to is the key the hardware signed into that report. It also checks that the processor identity and reported firmware match AMD’s certificate, that the current, committed and launch firmware versions are no older than this release accepts, and that the signed build came from Tinfoil’s release workflow for a tagged release and has not been revoked by this app. Only then does it send: each request body is sealed to that key on this device, the gateway forwards ciphertext it cannot open, and the reply comes back sealed under keys only that request could derive. "Sealed to TEE" means exactly that. Which software runs inside is established separately: Tinfoil's release workflow signs a statement naming each deployment's launch measurement, and Stewards verifies that statement on this device against Sigstore roots pinned in the app — the signature, the certificate chain, and the transparency-log proof — before showing "build verified" or allowing a request; the signed deployment digest must match the one the gateway supplies, and the signed launch measurement the hardware report. "Requests sealed" means all these checks passed. These checks run before every AI query, and every 15 minutes while Live monitoring is on; before a web search or page fetch they run against Tinfoil's search enclave, whose signed build must come from that enclave's own release workflow, and the query or address is sealed to it the same way. Missing, unavailable, malformed, unsupported, or failed evidence blocks requests, including stale evidence and a missing or invalid software signature, and raises an alert; the checkmark clears during verification and expires after one minute. A gateway cannot disable these checks by dropping its enclave information or claiming no confidential computing. Stewards tells you why a request was not sent and checks again on the next attempt; it never falls back to a readable AI request body, or to a search the gateway could read. That proves Tinfoil published the accepted router build the hardware measured, not that Stewards has independently audited or reproduced it. The router still selects downstream inference builds under Tinfoil’s policy; this app does not independently fix those downstream builds. Still not proven: freshness per request, since the report carries no nonce from this device; and the GPU's own attestation. When an endpoint makes no claim, offers no evidence, or proxies plaintext, the strip reads "Verification failed", and Stewards blocks requests until the enclave and build can be verified. Who runs it, and what is proof rather than promise: the enclave is Tinfoil's, a confidential-inference provider, and the model inside it is an open-weight model chosen by Stewards, which may change it as testing finds a better one; Settings › Security & Privacy › Protections names the one in use. The checks above are what keep this from resting on Tinfoil's good faith: a sealed request can be opened only inside a genuine AMD SEV-SNP enclave, whose memory the hardware keeps sealed from the machine's own operator, running a build Tinfoil's public release workflow signed into a public transparency log — so neither the Stewards Gateway nor Tinfoil's staff can read it, as far as that enclave's firmware carries AMD's published security fixes. Where it does not, the AI path reading and each send receipt name the missing fixes, and against whoever controls Tinfoil's servers the seal then rests on trust rather than proof; Stewards accepts firmware no older than a floor set in each release rather than holding every request until those fixes arrive. What is still taken on Tinfoil's word is narrower: that its published enclave code does what its public source says, because Stewards verifies the signature and the log entry rather than rebuilding it; that the GPU's own attestation checks out, which the enclave verifies at boot and Stewards does not repeat; and what Tinfoil keeps about a request — token counts, the model, and the time. A build that betrayed the first would be on the public record; the second and third are not something this app can check. The same reading carries the oldest Stewards build the gateway accepts: when a release changes what leaves this device or how the AI path is checked, an older version holds AI requests and web research until it is updated, and everything kept on this device stays available.

e. AI output can be wrong.

Responses may be incomplete, outdated, or confidently incorrect, including about law, accounting, and procedure. Stewards is not a law or accounting firm, provides no professional advice, and creates no professional relationship. Nothing it produces substitutes for your own judgment.

WHAT DETECTION CAN AND CANNOT DO

f. Detection is assisted, never guaranteed.

The scanner finds emails, phone numbers, dates, docket numbers, government ID numbers, long account numbers, street addresses, roster-style names, names from your Matter's titles and file names, and your glossary entries. It also uses the operating system's name recognition, which is best-effort: Stewards asks the system to fetch Apple's language assets when they are missing — a system request to Apple that carries none of your content — and if recognition is unavailable on your device it contributes nothing, silently, and it is weakest on non-Western names, all-capitals text, and tables. Known blind spots: short reference numbers, identifiers containing letters, partial or masked numbers, place names, relative dates ("last Tuesday"), a name that is also an everyday word (Price) unless your glossary lists it, and anything identifying only in context — "the partner who left after the Tulsa matter" names a person without matching any pattern. Treat every scan as a first pass for your review, not a clearance.

g. Files are read only on this device, some only in part, and some not at all.

Text that is already text is parsed on this device as the file imports: plain-text files and their dialects (Markdown, CSV, JSON, YAML, vCard, calendar files, source code), the text layer of PDF pages, Word (.docx and legacy .doc), Excel (.xlsx and .xls), PowerPoint (.pptx and .ppt, speaker notes included), OpenDocument (.odt, .ods, .odp), RTF, HTML and XML, and saved email (.eml, .emlx, and Outlook .msg). Files are read by what their bytes are, not by their extension, so a document saved under the wrong name still reads. Images — JPEG, PNG, HEIC, TIFF, and the other formats this Mac can decode — and PDF pages that carry no text layer are read instead by the operating system's on-device text recognition, which uploads nothing; the file's detail view shows progress while it runs. A PDF is handled page by page. A page that carries no text layer is recognized. A page that carries any text layer at all — a typed page, an earlier tool's OCR layer, or nothing more than a Bates stamp printed over a scan — is read from that layer alone and is never recognized, so whatever that page shows beyond its layer is not read. Text read in any of these ways is stored encrypted and then treated like any other file text: eligible for chat context, file actions, and backups under the file's stance, and it can carry reading and recognition errors.

The limits are real, and they are not edge cases. Recognition is best-effort and tuned for printed English: other languages, handwriting, stamps, faint or skewed scans, and tables can be misread or missed entirely. Recognition stops after 300 such pages in one PDF; pages with a text layer are still read past that point, and the extracted text then ends with a note naming the pages that were left unrecognized. Word and OpenDocument reading covers body text, not headers, footers, footnotes, comments, or tracked deletions. Spreadsheet reading covers cell values, and a date arrives as the number it is stored as. Email attachments are named but not opened. Pictures embedded inside a document are not recognized. The legacy binary Office formats are recovered structure by structure and are the likeliest to come back partial or garbled.

Some files are still never read at all: Pages, Numbers, and Keynote documents, anything password-protected or encrypted, and any format not named above. They import and are stored encrypted like everything else, but their contents have never been examined. Whenever a file's detail view shows no extracted text — or shows visibly less than the document holds — a scan reporting nothing found read nothing. Absence of findings is not evidence of absence.

h. A redacted copy is a new file; the original is untouched.

Redaction here is assisted, not certified: it produces a separate plain-text copy and leaves the original as it was, in the same Matter. The copy receives a neutral title and filename, with no part of the source name reused. Sharing the redacted copy rather than the original is on you. The copy loses formatting and inherits every limitation in (f) — it is not a certified redaction and not guaranteed identifier-free — and a shared original PDF may still carry metadata, annotations, and form fields Stewards never examined.

ON YOUR OWN COMPUTER

These four matter only if someone can read your disk — the same threat your files faced before Stewards existed, and one your operating system already answers with a device passcode and full-disk encryption (FileVault). Keep both on; Stewards cannot replace them.

i. Structure is visible even where substance is encrypted.

Titles of Matters, notes, conversations, and files, original filenames, file types, writing-style and sample names, and activity-record Matter names and destinations are encrypted with the local vault key. Each metadata record is authenticated to its model and record ID, so moving its ciphertext into a different record fails to decrypt. Existing stores are migrated before access; old label columns are cleared and the active database and journal compacted. This cannot erase copies already present in device backups, filesystem snapshots, or storage-hardware remnants.

Structural metadata remains readable: IDs and relationships, timestamps, counts, sizes, and policy flags can reveal when and how much the app was used. Other content fields, such as note bodies, use their existing encryption without record binding: someone able to write the store could transplant an intact body ciphertext into another note. The glossary is never included in an AI request; the represented party is encrypted at rest but accompanies discovery-drafting requests below Local-Only. Guarding the device and its key remains the passcode and FileVault's job.

j. App Lock is a screen, not a vault.

App Lock and screen privacy stop shoulder-surfing and app-switcher exposure. They encrypt nothing and add no protection against someone with access to the device's files — that is the passcode and FileVault's job.

k. Previewing briefly writes an unencrypted copy.

Previewing a file creates a temporary decrypted copy for the system viewer. Stewards deletes it when the preview closes and sweeps strays at launch; after a crash, a copy can persist until Stewards next starts. The system's Quick Look service, which draws the preview, may also render a thumbnail of the document into a cache of its own; that cache belongs to the operating system, so a small image of a previewed page can outlive the copy, and Stewards cannot clear it.

l. A backup is the one file that leaves by design.

An exported backup contains every Matter, Local-Only ones included — with original file bytes, your glossary, and the party each Matter says it represents — and every writing style with its samples and notes, encrypted under your passphrase. The passphrase is stretched with scrypt, a memory-hard derivation that makes offline guessing expensive even with dedicated hardware — but stretching only slows guessing, it cannot rescue a short or reused passphrase. Use a long, random passphrase from a password manager. There is no recovery: lose the passphrase and the archive is permanently unreadable. A Local-Only Matter is in the archive like any other: the file is written on this device and goes only where you take it, so the level's promise about what Stewards transmits is not what a backup tests — the passphrase is. An export can leave Local-Only Matters out, one export at a time, for an archive you mean to hand to someone else; a backup made that way cannot restore them. Because the encryption key is bound to this device and never moves, a Time Machine restore onto this same Mac brings everything back, but a different Mac — Migration Assistant, or a restore onto new hardware — cannot open the store: an exported Stewards backup is the only way to carry your Matters to another machine. For the same-machine case, keep FileVault on and back this Mac up with Time Machine.

YOUR OBLIGATIONS

m. Using Stewards does not discharge professional duties.

Confidentiality, privilege, conflicts, and data-protection obligations remain entirely yours. Whether transmitting a client's information to any AI service is permissible in your jurisdiction, engagement, or firm policy is a question you must answer before doing it. Stewards gives you controls; it does not give you permission.

3. HOW TO REDUCE YOUR RISK

In rough order of effect:

  1. Make genuinely sensitive Matters Local-Only — before you research or chat, not after. Local-Only is the only level that keeps titles, notes, files, and research out of AI requests entirely and off the web.
  2. Be deliberate about names in titles and filenames. They are encrypted on this device but, below Local-Only, travel with AI requests — scrubbed of glossary terms, the party, and detected identifiers in Standard and Guarded requests. New redacted copies use neutral titles and filenames that do not inherit any part of the source name. Code-name the Matter; record the real identity in the glossary or a note body. The glossary is never sent to the AI; the "We represent" setting is — it accompanies the requests the discovery drafter makes below Local-Only, including a topic suggestion.
  3. Write to the AI as if a stranger could read it — until the AI path reading can prove otherwise, one technically can. Say "the client," not the name. Message Check offers a substitution for glossary terms and structured identifiers; nothing else you type is filtered.
  4. Build the glossary early. Its terms are stripped from drafted queries unless a Standard Matter sends its queries unscrubbed, block Guarded searches while present, are replaced in the names that accompany Standard and Guarded AI requests, and are replaced in redacted copies. It is how a name is kept out of a web search: names Stewards merely detects are flagged, not removed. Matching ignores capital letters, and a term's middle initials are optional: "Jane Q. Doe" also matches "Jane Doe", but "Jane Doe" does not match "Jane Q. Doe". Enter names with their initials, and add every other form of each name you actually use.
  5. Open What’s Shared — the strip’s Request context cell, or the conversation menu on iPhone and iPad — to review exactly what accompanies requests, and switch off any note or file that shouldn't. Show request, beneath the composer, shows the request itself.
  6. Read the approval card before every search. It is the last point of control before the public internet.
  7. Share redacted copies deliberately: read one before sending it, never substitute the original, and never treat a file Stewards could not read as checked.
  8. Keep your device passcode and FileVault on; enable App Lock and screen privacy for over-the-shoulder privacy.
  9. Protect backups with a long, random passphrase from a password manager, and store the archive only where you would store the client files themselves. Export one before you move to a new Mac: the key does not move with the machine.
  10. Watch the AI path cell. When Stewards can cryptographically verify confidential compute, it will say so; until it does, assume it cannot.

4. NO WARRANTY

Stewards is provided "as is", without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. No security measure is perfect: the protections described here reduce risk and do not eliminate it, and nothing in this document guarantees that data cannot be disclosed. To the maximum extent permitted by law, the developers are not liable for any indirect, incidental, special, consequential, or exemplary damages, or for any loss of data, profits, business, or goodwill, arising from your use of Stewards.

You are responsible for deciding whether Stewards is appropriate for a given matter, and for the consequences of putting information into it.

askstewards.com · Built for the Mac · Privacy Policy · Terms of Use · How Processing Works · Security & Risk Disclosure