Calmbu
PRIVACY + SECURITY

Privacy is not a setting.It is the architecture.

Calmbu protects supported local Codex and Claude Code work on native Windows without needing to read it in the cloud. Encryption, integrity checks and recovery testing are built into every protected recovery point.

Local-first Authenticated encryption Stops on failed checks
Encrypted content Integrity checked
Recovery proof
Private recovery test passed

Your work stays private. Your backup proves itself.

The product is designed around two separate promises: keep the content confidential, and refuse to call it recoverable until integrity has been proved.

No agent content telemetry

Your sessions, prompts, instructions and workspace content do not become Calmbu analytics.

PRIVATE BY DEFAULT

Encrypted before destination writes

Backup content and sensitive workspace metadata are protected before reaching an external or cloud destination.

AES-256-GCM

Integrity checked

Incomplete or changed recovery data is detected before a recovery point can be trusted.

INTEGRITY PROOF

Complete recovery points only

Incomplete backup work is never presented as recoverable.

ALL OR NOTHING

Safe recovery boundaries

Recovery is restricted to approved destinations and stops safely when validation fails.

SAFE BOUNDARIES

No vendor back door

Your recovery code is machine-independent and yours. Calmbu cannot recover a code it never had.

YOU HOLD THE KEY

Built for the failures backups meet in real life.

A backup can fail quietly through damage, interruption, theft or a restore that was never tested. Calmbu applies safeguards across encryption, integrity and recovery.

Lost or failed PC Customer-controlled recovery material and supported device migration
Stolen drive or cloud copy Encryption before the destination receives data
Bit rot or hostile modification Integrity validation before recovery data is trusted
Interrupted backup Incomplete work is never presented as recoverable
Unsafe recovery destination Guarded recovery boundaries and safe failure

Your agent content is not Calmbu's business.

Calmbu keeps coarse operational information local and uses privacy-safe error codes. It does not need the substance of your work to protect it.

  • No content telemetry: sessions, prompts and instructions do not become analytics.
  • No forced Calmbu cloud: choose a local, external, OneDrive or supported replica location.
  • Protected backup metadata: sensitive workspace details are encrypted with the backup.
  • No recovery-code escrow: the code is yours to keep somewhere separate.

Security also means being honest about limits.

Calmbu can protect the backup. It cannot make an already-compromised Windows account safe or recreate a recovery code nobody kept.

Can malware running as me read the original files?

Yes. Software running as your Windows account can already access the same original agent files. Calmbu protects copies at rest; it cannot neutralise an infected account.

Is a continuously connected drive ransomware-proof?

No. Use disconnected media or an appropriately locked immutable replica when ransomware resilience matters.

What happens if the recovery code is gone?

If every device unlock key is also gone, the encrypted data is intentionally unrecoverable. That is the consequence of having no vendor back door.

Does Calmbu include sign-in credentials?

Known credential and private-key material is excluded from standard protection. You may need to sign in again after recovery.

PRIVATE WORK DESERVES PRIVATE PROTECTION

Protect your agent workspace without handing your work over.

Calmbu keeps the protection journey on your terms—from encryption to recovery proof.

See how Calmbu works No admin access required