0910

ToshLLM field guide

Privacy and security

Learn what remains local, what benchmark sharing sends and how ToshLLM protects submission identity.

Local by default

Model inference stays on the Mac.

ToshLLM runs model inference locally and binds its API to 127.0.0.1 by default. Downloaded models, saved conversations and benchmark history remain on the Mac unless you enable a feature that communicates with another service.

Network features have visible purposes, including model downloads, update checks, remote MCP servers, optional local-network serving and voluntary benchmark sharing. Local inference does not make a remote tool or operating-system service local.

Benchmark consent

Nothing is submitted on view appearance.

An installation that never starts the share flow makes no benchmark-sharing request. The first share creates or loads a device identity, obtains a server challenge, runs the workload and presents a review. Upload begins only after you choose Sign and send benchmark.

The signed payload includes model identity and artifact hashes, hardware description, macOS and app versions, runtime configuration, individual measurements and sanitized benchmark evidence. A pseudonym is optional.

Cryptographic identity

The private key does not leave Keychain.

ToshLLM creates a P-256 signing key on first use. It prefers the Secure Enclave when available and falls back to a software P-256 key stored as a device-only Keychain item. The server receives the public key and fingerprint, never the private key.

Each upload uses a short-lived nonce and signs a domain-separated message containing the challenge, nonce and SHA-256 hash of the reviewed payload. This prevents a copied submission from being silently edited or replayed as a new result.

You can reset the identity.

The next share then starts a fresh, unlinkable installation identity. Earlier public submissions retain their original fingerprint.

Local API

Network access is your choice.

Local-network discovery is off by default. If you enable it, ToshLLM listens on every network interface and advertises the API with Bonjour. Enable API-key protection and use this mode only on networks you trust.

Health and model-list endpoints remain public for client discovery even when the API key is enabled. The key protects inference and other non-public operations, not the existence of the server or its model IDs.

Agents and MCP

Tool boundaries depend on what you enable.

Built-in agent tools can read files, edit files and run commands after the permission flow. A remembered permission applies to future calls of that tool until you revoke it. Configure a container or SSH runtime when agent code should not execute in the app's local environment.

An MCP server receives the calls, arguments and resources required for the operation. If its URL is remote, that information leaves the Mac. Authentication headers for MCP servers are stored in macOS Keychain.

Microphone and dictation

Recording and transcription are different paths.

Recording creates a temporary local WAV file and attaches its bytes to the local model. Dictation uses Apple's Speech framework and requests on-device recognition when it is supported for the current language.

Some languages may not support on-device dictation.

In that case macOS can use Apple's speech service according to the system's Dictation settings and privacy terms. Use audio recording with a local audio-capable model when transcription must remain inside the local inference path.

Network destinations

Know why a connection happens.

Hugging FaceSearches model metadata and downloads model artifacts that you select.
GitHubChecks ToshLLM releases and downloads an update only after your action.
toshllm.comReceives a benchmark only through the explicit review, sign and send flow.
Local clientsReach the running model through localhost or the trusted local network mode you enable.
MCP serversReceive tool calls, resources and prompts only after you add and enable that server.
Apple SpeechMay process dictation when on-device recognition is unavailable for the current language.
Keychain prompts

Development builds may ask again.

The benchmark signing key and optional local API key are stored in macOS Keychain. A development build with a changed temporary code signature can cause macOS to ask for the login password before that new build may reuse an existing item.

A stable Developer ID signature and Apple notarization preserve the application's identity across normal updates. The password prompt belongs to macOS; the password is not sent to ToshLLM or included in a benchmark.

For teams and individuals

Make ToshLLM work for your team.

Need a tailored deployment, help choosing models, or guidance for a fleet of Intel Macs? Tell us what you are building and we will get back to you personally.

Found a reproducible bug? A public GitHub issue helps everyone follow the fix. Open an issue ↗
hello@toshllm.com

CONTACT / TOSHLLM

Your message goes directly to ToshLLM. Please do not include passwords, API keys, or private logs.