Blog
Zero-Cloud Architecture: How Tactic Remote Keeps Your Code on Your Machine
Tactic Remote operates on a zero-cloud architecture where all code execution, session data, and file access remain on the developer's Mac, with direct encrypted connections between iPhone and Mac that bypass our infrastructure entirely.
Follow product and engineering updates from this channel.
Browse categoryEvery week brings a new story about an AI tool that uploaded source code to a cloud service, trained on proprietary data without consent, or exposed development environment credentials through a misconfigured API. Developers are right to be skeptical of tools that touch their codebase.
Tactic Remote was designed around a simple principle: source code should not be uploaded to Tactic Remote-managed cloud services. This article explains how that works, where the trust boundaries are, and what we can and cannot see.
What "Zero-Cloud" Means
Tactic Remote has no cloud backend. We do not operate servers that relay, store, or process your development data. The connection between your iPhone and your Mac is direct.
In local network mode, "direct" means literally direct — your iPhone communicates with your Mac over your local Wi-Fi network. No traffic leaves your network. No DNS resolution hits external servers. The connection is between two devices on the same subnet.
In Cloudflare Tunnel mode, traffic routes through Cloudflare's edge network to reach your Mac when you're outside your local network. Cloudflare provides the transport layer, but the application-layer payload is encrypted end-to-end between your iPhone and your Mac companion app. Cloudflare sees encrypted bytes. We see nothing.
To be precise about what "zero-cloud" covers:
- Source code — not transmitted to Tactic Remote services. File contents read by Claude Code stay on your Mac. When file diffs are shown in the iPhone app's approval view, they travel directly from your Mac to your iPhone.
- Session transcripts — the conversation between you and Claude Code stays on your Mac. The iPhone receives a stream of terminal output for display, but this stream goes Mac-to-iPhone with no intermediary we control.
- Shell command output — stays on your Mac. Streamed to your iPhone for display, not stored elsewhere.
- Approval decisions — travel iPhone-to-Mac. We have no record of what you approved or denied.
- Push notification payloads — this is the one area where we interact with Apple's infrastructure. See the detailed discussion below.
Authentication Between iPhone and Mac
When you pair your iPhone with your Mac companion, the devices establish a shared secret through one of two methods:
QR code pairing. The Mac companion generates a QR code containing a one-time pairing token and the Mac's local network address. You scan it with the iPhone app. The devices exchange cryptographic keys over the initial connection, and subsequent connections authenticate using these keys. The pairing token is single-use and expires after 60 seconds.
Manual code entry. For situations where QR scanning isn't practical, the Mac companion displays a 6-digit code. You enter it on the iPhone. The code serves the same purpose as the QR token — it bootstraps the key exchange.
After pairing, authentication is automatic. The iPhone presents its stored key on each connection, and the Mac companion validates it against the authorized device list. No passwords, no tokens to rotate, no OAuth flows.
Pairing data is stored in the macOS Keychain on the Mac and in the iOS Keychain on the iPhone. Both are hardware-encrypted storage provided by Apple's Secure Enclave.
Trust Boundaries
Every security model has trust boundaries — the lines where you must trust something external. We want to be explicit about ours:
You trust Anthropic's Claude Code
Tactic Remote is a control layer around Claude Code. Claude Code itself communicates with Anthropic's API to generate responses. Your prompts and Claude's responses transit Anthropic's servers. This is inherent to using Claude Code and is not something Tactic Remote adds or can remove. Anthropic's data handling policies apply to this traffic.
You trust Apple for push notifications
When the Mac companion needs to wake your iPhone to deliver an approval request, it sends a push notification through Apple's Push Notification service (APNs). The notification payload contains a minimal alert — the session name and action type (e.g., "Claude wants to run a shell command"). It does not contain the actual command, file contents, or any source code.
We designed the notification payload to be as minimal as possible. The detailed approval information is fetched by the iPhone app directly from your Mac when you open the notification. Apple sees that you received a notification from Tactic Remote. Apple does not see what Claude Code is doing.
You trust Cloudflare (tunnel mode only)
If you use Cloudflare Tunnel for remote access, traffic transits Cloudflare's network. As discussed in our Cloudflare integration article, the transport layer is Cloudflare's, but the application payload is encrypted with keys Cloudflare does not possess.
You trust your local network (local mode only)
In local network mode, the connection is only as secure as your Wi-Fi network. On a trusted home or office network, this is fine. On a public Wi-Fi network, local mode traffic could theoretically be intercepted. We use TLS for the WebSocket connection regardless of network type, but we recommend Cloudflare Tunnel mode when connecting over untrusted networks.
What We Can and Cannot See
We believe transparency about data access is non-negotiable. Here is a precise accounting:
| Data | Can we see it? | Explanation |
|---|---|---|
| Source code | No | Not sent to Tactic Remote services; typical flow is Mac-to-iPhone |
| Session transcripts | No | Mac-to-iPhone only |
| Commands executed | No | Mac-to-iPhone only |
| Approval decisions | No | iPhone-to-Mac only |
| Files read or written | No | Local to your Mac |
| Notification delivery status | Yes | Apple reports delivery status |
| App crash reports | Yes (opt-in) | Standard iOS crash reporting |
| Usage analytics | Yes (opt-in) | Session count, duration — no content |
Opt-in analytics, if enabled, contain only aggregate usage metrics: how many sessions were started, average session duration, connection mode distribution. No content, no file paths, no command text. Analytics can be fully disabled in the iPhone app's settings.
Network Architecture
The following describes what happens at the network level during a typical Tactic Remote session:
Local Network Mode
Your router sees local traffic between two devices. Your ISP sees nothing related to Tactic Remote. The only external traffic is Claude Code's communication with Anthropic's API, which happens regardless of whether Tactic Remote is involved.
Cloudflare Tunnel Mode
Cloudflare sees encrypted application traffic. The cloudflared daemon on your Mac terminates the Cloudflare tunnel and forwards traffic to the Mac companion on localhost. No external party other than Cloudflare's edge network handles the traffic, and Cloudflare cannot decrypt the application-layer encryption.
Threat Model
We've considered the following attack scenarios and how the architecture addresses them:
Compromised Wi-Fi network. TLS on the WebSocket connection prevents passive eavesdropping. An active attacker performing a TLS interception (MITM) attack would need to compromise the certificate pinning in the iPhone app, which is a high-complexity attack.
Stolen iPhone. The Tactic Remote app requires biometric authentication (Face ID or Touch ID) to open. Pairing keys are stored in the Secure Enclave and are not extractable even from a jailbroken device. A stolen iPhone cannot approve actions or view session data without the owner's biometric.
Compromised Mac. If an attacker has access to your Mac, they have access to everything Claude Code can access — this is true with or without Tactic Remote. Tactic Remote does not expand the attack surface of a compromised Mac.
Rogue Mac companion update. The Mac companion is distributed as a signed binary through our website. macOS Gatekeeper validates the code signature before execution. We do not have the ability to push silent updates — the user must download and install updates manually.
Why This Matters
The trend in AI-assisted development tools is toward cloud-hosted agents that run in sandboxed environments and access your code through repository integrations. This model works for some teams, but it requires trusting the tool vendor with your source code, your credentials, and your development workflow.
Tactic Remote takes the opposite approach. Your Mac is the execution environment. Your code stays on your disk. Your credentials stay in your keychain. The only AI service involved is Claude Code's existing relationship with Anthropic's API, which you already agreed to when you installed Claude Code.
This architecture has costs. You need a Mac that stays powered on. You need to manage your own network connectivity. You don't get the convenience of a cloud dashboard that works from any browser.
We think the tradeoff is worth it. For developers working on proprietary software, handling sensitive data, or operating in regulated industries, the ability to say "my code was not uploaded to the app vendor's cloud" isn't a feature — it's a requirement.
For security hardening recommendations and detailed configuration guidance, see our Security and Network Hardening documentation.
Try Tactic Remote
Control your coding Agents from your phone
Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.