Trust & Security

Local-first, account-scoped remote control

FlyDex controls local Codex sessions through a desktop connector. That connector binds to localhost only and keeps outbound connectivity to FlyDex.

No inbound ports Localhost only Short-lived pairing

Connection model

How access is protected

Local binding

Connector API binds to 127.0.0.1 only.

Outbound relay

No inbound port forwarding to your desktop is required.

Account isolation

Machines are scoped to the account that paired them.

Pairing model

QR-only onboarding

Short-lived claims

Pairing handoff tokens expire quickly and are single-use.

Phone sign-in

Auth completes on your phone, then desktop setup finalizes automatically.

One command install

Desktop setup uses one npx command.

Data at rest

What FlyDex stores

Stored

Account metadata, billing state, machine metadata, and audit metadata.

Not stored at rest

Chat content, Codex output, thread previews, token usage summaries, and completed prompt bodies.

Help

Security reports and support