Baltor Get started

Know what you share. Control what runs.

Connecting to Baltor grants access to permitted material. It does not give the service permission to run commands on your computer.

  • Two kinds of access

    Your Baltor key reaches the library. Your model key stays in your harness, and Baltor never asks for it.

  • Files cannot run themselves

    A downloaded file grants no permission to run anything. Your harness decides, with the permissions you set.

  • Exact bytes, every time

    Search returns references. A file arrives only through a download that names the SHA-256 of its exact bytes.

  • Effects need authority

    An item that declares effects on your computer, such as reading or writing files, says so before you download it, and your harness sets what each step may do.

Service access and model access are separate

A service token identifies a scoped tenant connection. The service stores token digests, checks scope and expiry, and can revoke access. Your model provider keys belong with your local client or approved credential broker. Do not enter them into the website.

An email sign-in lasts as long as your browser tab: the page keeps it in the tab's session storage, so reloading keeps you signed in, and closing the tab or signing out ends it. A service token or client token entered on the sign-in page stays in page memory only, and reloading clears it. Avoid shared devices, untrusted extensions and screenshots of credentials.

Selected files do not grant execution authority

Search returns permitted metadata. Fetching a body rechecks access and its exact identity. A digest proves that bytes match the selected reference; it does not prove that the material is safe, correct or useful.

Inspect unfamiliar code and plugins. Use a confined workspace and a sandbox appropriate to the work, with explicit file, command and network permissions. A shared container does not isolate one process from every other process inside it.

How review works

An item joins the library only after independent reviewers approve its exact bytes. No reviewer judges an item it wrote, and one written rejection keeps an item out, with the reason recorded.

Since September 24, 2026, a new item needs approval from at least two reviewers of at least two model families, none of them from the family of the model that wrote the item. Each reviewer reads the item as a customer would and judges it against written criteria: the practice it describes is sound, what it says about its cited source is true, its licence is settled, and it declares every effect its steps have on your computer, such as reading or writing files.

Before any reviewer reads an item, automated checks refuse it for a licence that is not accepted or that disagrees with the licence the item declares, a missing part, unsafe instructions such as a download piped into a shell or a read of a credential file, declared effects that do not match its steps, a value shaped like a credential, or a copy of another item. Material from outside sources also needs a record of where its exact bytes came from.

The approval record names each reviewer, with its decision and its reasons. The library's first 43 items were approved on September 21, 2026, before the rule on model families: three reviewers who wrote none of them, one for correctness and usefulness, one for provenance, licence and safety, and one adversarial, each approved every one of those items, and 6 of the 49 items they judged were rejected. One of those reviewers came from the same model family as the model that wrote the items.

Approval gives an item no permission to run anything. The digest proves that the bytes you download are the approved bytes; it does not prove that they suit your task.

What reaches this service

Search text, requested references and service authentication reach the server when you use the workspace. The service records access and usage metadata. The website does not automatically upload your project files, model keys or complete execution traces.

Do not send private customer content yet. The final retention policy, deletion workflow and consent controls remain launch work, and we would rather say that than let you assume otherwise. Embeddings and derived features must not be treated as anonymous data.

Current operational limits

The service runs on one Fly machine in one region with an attached persistent volume. A local backup-and-restore exercise has passed. This is not a multi-region service, an availability guarantee, an independent security audit or a compliance certification.

You sign in with your email address and password. Client tokens for your tools are created and revoked on your account page, and a client token cannot manage your account, your billing or other tokens.

Before sensitive or consequential work

Read the privacy notice for what the service stores, and set the permissions of each task in your own harness. Keep provider credentials out of prompts and retrieved files. Do not repeat an external action after an uncertain outcome until its state has been reconciled.

Reviewed files, your controls

Baltor Pro, $29 a month. Cancel any time.

Get started