Skip to content

Remote

Security

How Codz Remote keeps your Mac in charge, with approved projects only, end-to-end encryption and pairing you approve on the phone.

Codz Remote is built so that your Mac stays in charge. The Mac runs every agent with its own logins and decides what a phone may see and do. The phone, and the relay that carries messages between the two, only ever handle encrypted messages.

This page describes those guarantees and the controls you have over them. For setup, see Codz Remote.

Your Mac is in charge

  • Agents run on the Mac. Every chat, command and edit happens on your Mac, with the provider logins you already have there. The phone never receives provider credentials.
  • The Mac checks every request. A phone asks for something; the Mac decides. It applies the projects you approved and the same approval rules as at your desk, so an agent that asks before running a command still asks, whether the answer comes from the Mac or the phone. See Modes & approvals.
  • No arbitrary paths. The phone names an approved project and a file inside it. The Mac refuses a path that leads outside the approved folder.
  • No arbitrary ports. A preview from the phone’s Browser can only reach a local server the Mac lists for that approved project.
  • Mac controls stay on the Mac. System Settings and permission panes are shown to the phone as status only. Codz never changes them remotely.
  • Nothing waits for an offline Mac. When the Mac is asleep or Codz has quit, the phone shows its last snapshot read-only and sends nothing. Commands are not queued for later.

Only the projects you approve

The phone sees only the folders you add under Settings ▸ Connections ▸ Projects your phone can use: their chats, files and tools, and nothing else on the Mac. Chats in other folders, and side chats, are never sent to the phone.

Removing a project with Remove takes it away from every connected device. A phone that tries to use it afterwards is told the project is no longer shared with it.

End-to-end encryption

Everything a phone and your Mac say to each other is encrypted on the device that sends it and can only be opened by the device it is for.

  • A key per pairing. Each phone and Mac pair has its own key, agreed between the two devices. Codz’s servers never have it.
  • Servers carry ciphertext. Codz’s servers route encrypted messages. They never receive your prompts, paths, commands, files, diffs, terminal output, screen captures, provider tokens or pairing keys.
  • Previews too. A local server you preview on the phone reaches it through the same encrypted connection. The relay sees only encrypted data and the details it needs to deliver it.
  • Replays are refused. Every message is signed and numbered. The devices, and the server, reject a message they have already seen.
  • Notifications say nothing sensitive. A push notification carries one fixed sentence, such as “An action needs your review.” It never includes prompts, code or output.

For the technically curious: the pairing key comes from an X25519 key agreement with HKDF-SHA256, every payload is encrypted with ChaCha20-Poly1305, and message headers are signed with P-256.

Pairing you approve

Connecting a phone takes a code from your Mac and an approval on the phone.

  • A one-time code. The code your Mac shows works once and expires after five minutes. Its secret part never reaches a server, even when the phone opens it in a browser. Closing the setup window cancels the code.
  • You approve on the phone. Codz Remote names the Mac it is about to connect to, for example Connect to “MacBook Pro”?. Nothing is sent until you tap Approve and confirm with Face ID, Touch ID or your passcode.
  • The phone checks the Mac. The code identifies the Mac that showed it. If a different Mac answers, the phone withdraws the connection and says: “This code doesn’t match the Mac that answered, so the connection was withdrawn.”
  • The Mac accepts only its own code. Your Mac accepts the pairing that its code on screen produced. Any other pairing, such as one completed after you closed the code, waits in Settings ▸ Connections as Requires authorization until you click Allow or Deny.
  • Your account only. Only devices signed in to your Codz account can discover the Mac or see its name.

Face ID before changes

Anything that changes your Mac asks for Face ID, Touch ID or your passcode before it is sent. That covers starting a chat, sending a message, approving an action, committing, running a terminal command, saving a file and starting a preview.

  • Reading, stopping work and denying an action do not ask.
  • One confirmation covers the same Mac for a minute while Codz Remote stays open. Switching Macs or leaving the app ends it.
  • If you cancel, Codz Remote says “Face ID was not confirmed, so nothing was sent to your Mac.”

On the phone

  • A sealed offline copy. Codz Remote keeps the last snapshot of each Mac so you can read it offline. It is sealed with keys that never leave the device, and it is read-only.
  • Pro keeps it live. If your Pro plan ends, cached data stays readable but nothing can be sent.
  • Signing out erases it. Sign out unpairs the phone and erases its keys and offline copy.

Revoking access

You can cut a device off from either side:

  • On the Mac: Settings ▸ Connections, then Revoke access on the device. It can no longer see or control the Mac.
  • On the phone: Settings ▸ Macs, then Revoke on the Mac. Future encrypted messages for that pairing are deleted.
  • Everything at once: turn off Allow connections in Settings ▸ Connections.

Revoking stops what happens next. Content a device has already decrypted cannot be recalled.

If your Mac is ever issued a new remote identity, every existing pairing stops working and Codz says: “This Mac was issued a new remote identity, so paired devices must be paired again.” Connect each phone again with Set up.