Privacy and encryption

Encryption keys, rotation, and recovery

Keep encrypted history readable and recover from a temporarily missing key.

End-to-end encryption protects event content between your computer and your devices. Each paired computer has a root key. Optional rotation derives epoch keys so different periods use different encryption keys.

The recommended installer setup enables end-to-end encryption. Key rotation is off by default, and Key Retention defaults to Keep All.

Approval Mode creates a service-encrypted copy of the complete command information needed for centralized policy evaluation. The service opens that copy in request memory, evaluates policy, and does not write it to event history or request logs. The copy is discarded when the request finishes. A separate device-encrypted copy is used for live review and event history, subject to your Privacy Level. Other supported activity, such as prompts, responses, thinking, and command output, can remain encrypted for your devices.

If you turn end-to-end encryption off, new content still travels over HTTPS and retained content is encrypted at rest on Agent Approve servers. Agent Approve can process that new content without device-held end-to-end encryption keys. Existing keys remain on your device, so the app can continue opening older encrypted events while those keys are available.

Turning end-to-end encryption off does not decrypt older events or remove their keys. If you later remove a key, events encrypted with that key become unreadable unless you can recover the key from iCloud Keychain or the paired source computer.

View your keys

Open Settings > Privacy > Encryption Keys. The screen shows root keys used for pairing and derived epoch keys created by rotation. Keys sync through iCloud Keychain when Keychain sync is available for your Apple account.

Do not remove a root key unless you accept losing access to every event encrypted by that root key or one of its derived keys.

Rotation period

When rotation is enabled, choose an hourly, daily, weekly, or monthly period. Rotation limits how much history one current key can open if that key is later exposed.

Key retention

OptionEffect on older encrypted events
Keep AllKeeps the root key so retained history remains decryptable on the device.
Keep Last 7Older events become unreadable after seven rotation periods.
Keep Last 30Older events become unreadable after thirty rotation periods.
Discard (Forward Secrecy)Keeps only the current window needed for recent events. Older events become unreadable.

Key Retention is separate from Data Retention. One controls keys on your device. The other controls how long events stay in your history.

If an event says its key is missing

A brief mismatch can appear around rotation or while iCloud Keychain is catching up.

  1. Refresh the event or return to the list and open it again.
  2. Open Settings > Privacy > Encryption Keys and tap Sync from iCloud.
  3. Quit Agent Approve and reopen it so the app reloads the Keychain.
  4. Confirm that iCloud Keychain is enabled and that the device uses the same Apple account as the device that holds the key.

If the key was intentionally discarded by Key Retention, removed from Keychain, or replaced during a new pairing, refreshing cannot recreate it. Re-pairing creates a key for new events but does not recover an old key.

Never send an encryption key, pairing code, or key file to support.

Go out and grab a coffee

We'll ping you if your agents need you. Try Agent Approve free for 7 days.