
Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.
Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.
Install · Quick start · Policies · Monitoring · Pi / OMP · Security
Cover is a bidirectional privacy proxy for AI coding agents. It replaces matched sensitive values locally with realistic, deterministic stand-ins before a request leaves your machine, then translates matching fakes in normal and streaming responses back to the originals. The model gets coherent context; your agent and tools keep working with the real environment.
Use reversible pseudonymize or placeholder rules when the conversation must
keep working end to end. Use one-way mask or redact rules when restoration
is unnecessary, block to stop a request locally, and allow for an explicit
exception.
Supported clients include Codex, Claude Code, Cursor, Pi / Oh My Pi, and OpenAI- or Anthropic-compatible SDKs and routers.
The installer downloads the release for your OS and CPU, verifies it against
the published SHA-256 checksums, installs it atomically to
~/.local/bin/cover, configures selected clients, and starts the proxy.
curl -fsSL https://raw.githubusercontent.com/DavidCarliez/cover/main/scripts/install.sh | bash
No Go toolchain or Git checkout is required. You only need curl, an archive
extractor (tar on Linux/macOS or unzip on Windows), and sha256sum,
shasum, or openssl for verification.
Prebuilt Linux, macOS, and Windows archives and their checksums are available from GitHub Releases.
For a non-interactive install:
curl -fsSL https://raw.githubusercontent.com/DavidCarliez/cover/main/scripts/install.sh | \
COVER_AGENTS=openai,claude bash
Pin a release or install only the binary with environment variables applied to
the bash process:
curl -fsSL https://raw.githubusercontent.com/DavidCarliez/cover/main/scripts/install.sh | \
COVER_VERSION=v0.1.0 COVER_SKIP_SETUP=1 bash
git clone https://github.com/DavidCarliez/cover.git
cd cover
go build -o cover ./cmd/cover
install -m 0755 cover ~/.local/bin/cover
The core binary has no cgo dependency. Standard Go cross-compilation works:
GOOS=linux GOARCH=arm64 go build -o cover-linux-arm64 ./cmd/cover
GOOS=windows GOARCH=amd64 go build -o cover.exe ./cmd/cover
| Area | Cover functionality |
|---|---|
| Policy | Declarative rules with allow, placeholder, pseudonymize, mask, redact, and block actions |
| Realistic replacements | Deterministic generators for IP addresses, hosts, domains, emails, usernames, passwords, UUIDs, URLs, and aliases |
| Context-aware rules | Whole-value protection by JSON key, including short passwords such as admin, plus regex and built-in detector selectors |
| Stable identities | Installation-keyed HMAC pseudonyms remain consistent across requests, sessions, and restarts |
| Mapping safety | Bounded, session-isolated, memory-only reversible mappings with TTL and capacity limits |
| Inspection | cover inspect previews the protected JSON without contacting an LLM |
| Diagnostics | cover doctor verifies policy, daemon health, local fail-closed behavior, and Codex routing |
| Monitoring | Metadata-only audit and monitor views, plus explicit live-only inspection of caught and forwarded content |
| Proxy hardening | Loopback-by-default listeners, body and stream limits, generic safe errors, and fail-closed parsing |
| Streaming compatibility | OpenAI Responses, Chat Completions, and Anthropic SSE restoration across delta events, heartbeats, and interleaved channels; JSON-safe tool arguments |
| Codex compatibility | Responses API and router configuration, compression checks, and immutable encrypted_content fields |
| Optional semantic pass | A local llama.cpp detector can inspect free-form text that regular expressions miss |
cover init # write ~/.config/cover/config.yaml
cover start --detach # run in the background
cover doctor # verify the local setup
cover test # local redaction round trip, no network call
cover monitor # watch privacy-safe request metadata
cover init prompts for OpenAI, Anthropic, or a custom upstream. The complete
configuration is documented in configs/config.example.yaml.
| Command | Purpose |
|---|---|
cover install | Configure clients, shell exports, and the background proxy |
cover init | Create the configuration file |
cover start [--detach] | Start Cover in the foreground or background |
cover stop | Stop the background process |
cover restart | Restart it in the background |
cover status [--json] | Show process, listener, and redacted upstream status |
cover version [--json] | Show build version, commit, and date |
cover update [--version vX.Y.Z] | Install a verified GitHub release; restart and check health if running (Linux/macOS) |
cover update --rollback | Restore the previous binary, preserving configuration |
cover env | Print shell exports for configured clients |
cover test | Run a synthetic local redaction and restoration check |
cover inspect request.json | Preview exactly what Cover would forward |
cover doctor [--json] | Run configuration, privacy, daemon, and routing checks |
cover monitor | Show recent safe metadata and follow new events |
cover monitor --show-content | Show sensitive live transformations and outbound JSON |
cover models pull | Download the optional local detector runtime and model |
cover models status | Report local detector installation and configuration |
cover completion | Generate shell completion scripts |
Stopping Cover does not change client configuration. A client still pointed at Cover will fail to connect until Cover is restarted or the client is pointed back to its direct provider or router.
Stops and restarts drain active requests for up to 30 seconds, configurable
with shutdown_timeout_ms. After that deadline, remaining connections close.
New connections can fail briefly during restart; this is not a zero-downtime
handover. cover status and cover doctor report when the running daemon
differs from the installed binary.