Local-first CLI
The CLI operates on local repositories. This release does not transmit CLI usage telemetry to CodexFlow.
Signed activation
Paid activations use Ed25519 signatures over canonical JSON. The CLI verifies the signature against embedded public trust roots.
Signed payload
The workflow payload manifest is signed, and the archive sha256/size are verified before install.
No hidden LLM calls
CodexFlow installs workflow files and commands. It does not secretly call model APIs on your behalf.
Watermark limitations
Watermarks record license metadata for emitted premium assets. They are not a remote revocation mechanism.
Commerce records
Website records are limited to checkout, fulfillment, access/download, fraud, refund, and dispute evidence.