Skip to content
Pacific Machines
ProductDocsChangelogStatusPrivacy PolicySecurityTermsBook a call

Whitepaper

Security whitepaper

Last updated September 22, 2026

Public overview of how Reefo, Inc. protects Pacific Machines — architecture, access, encryption, vendors, incidents, and compliance. No sign-in required. Version 2026.09.

Contents

  • Purpose and scope
  • Security program
  • Product architecture
  • Identity and access
  • Encryption
  • Secure development and releases
  • Vendors and subprocessors
  • People and endpoints
  • Incidents and vulnerability disclosure
  • Shared responsibility
  • Compliance status
  • Related public documents

Purpose and scope

This whitepaper describes how Reefo, Inc. ("Pacific Machines", "we") protects the Pacific Machines desktop application, related cloud services, and pacificmachines.ai. It is written for security, legal, and procurement readers who need a public, no-login summary of our program.

It covers:

  • The product security model (what stays on the device vs. what uses the cloud)
  • Access control, encryption, and release integrity
  • Vendors, people, incident response, and vulnerability reporting
  • Current compliance status

Contractual terms live in the Terms of Service. Data collection, retention, and user controls live in the Privacy Policy. Operator how-to lives in product documentation. This document is not a SOC 2 report, not a HIPAA certification, and not a substitute for a signed agreement.

Version 2026.09 · Classification: public

Security program

Pacific Machines is operated by Reefo, Inc., based in San Francisco. We maintain a documented information security program. Approved internal policies cover access control, operations, cryptography, secure development, risk management, vendors, human resources, asset management, business continuity, and incident response. Those policies are reviewed at least annually.

Roles for designing, operating, and monitoring security controls are assigned in job descriptions and in our information-security roles policy. Production access is limited to authorized personnel with a business need.

Current examination

We are currently in process with Vanta toward SOC 2 Type II and expect to obtain SOC 2 in the coming weeks. Until an independent report is issued, we are not SOC 2 certified. Do not treat this whitepaper, our Trust Center, or marketing materials as a completed attestation.

Product architecture

Pacific Machines helps a company decide what to automate with AI by learning from approved real work. Capture begins on the user's computer. A person reviews evidence and decides what should move forward. The product does not deploy automations on its own.

What we observe

Learning uses approved screen and accessibility signals while it is turned on. Audio is not captured. Meeting transcription is not part of the product.

By default Learning runs in Low mode: app, window, and activity context sufficient to rebuild a day, without continuous screenshots, OCR frames, or video. Users may opt into High mode, which adds screenshots, OCR, and richer visual saves.

Operating-system permissions gate capture. On macOS that includes Screen Recording and Accessibility; Input Monitoring may be requested so Learning knows when work is happening. Pacific Machines cannot override those OS controls. Revoking screen recording stops capture.

What stays on the device

By default, Learning evidence is stored locally on the user's computer under ~/.jarbas (UI brand: Pacific Machines; on-disk root unchanged). The full capture library (db.sqlite and frame files) is not mirrored to a remote learning store. We do not stream live screen video to the cloud.

What uses the cloud, on purpose

FunctionWhat is sent
Sign-in and organization membershipIdentity needed to authenticate the user (Clerk). Not the capture database.
Brain syncMarkdown Brain documents such as daily recaps and workflows (Convex) — not db.sqlite or screenshot frames
Shared team reportsThe recap or report the organization chose to create (Convex)
Chat and AgentContext assembled for that request, sent to the model provider
PluginsCalls to tools the user or organization explicitly connected
WebsiteContact you submit and product analytics designed not to include raw screen content

Controls available to the user

  • Pause or stop Learning; choose Low or High Learning mode
  • Ignore lists for apps and URLs (saving the list applies going forward and does not delete past captures)
  • Text cleanup that replaces common secrets and personal data in stored text with labeled placeholders
  • Date-range delete or a full local reset from Settings → Storage

Cleanup is pattern-based. It can miss sensitive data that does not match a rule, and it edits stored text, not pixels in screenshot files when those files exist. Enable automatic cleanup when a recording ends to shrink the window where Chat might see uncleaned text. Full file paths, detection categories, and limitations are in the Privacy Policy.

Identity and access

Customer and employee access to Pacific Machines accounts uses unique identities through our identity provider (Clerk). Organizations manage seats and membership. Privileged access to production systems is restricted to authorized personnel and revoked when employment or contractor access ends.

Personnel acknowledge information security, confidentiality, and acceptable-use policies. User access to in-scope systems is based on role, or requires a documented request and approval, in line with our Access Control Policy.

Customers are responsible for protecting their own account credentials, for choosing who joins their organization, and for configuring capture permissions, ignore lists, Learning mode, and cleanup on each device.

Encryption

In transit

The public website and cloud APIs are served over HTTPS (TLS). Chat, Agent, authentication, Brain sync, and shared-report traffic to our providers also uses encrypted connections.

At rest (cloud)

Cloud services we use for authentication, Brain sync, shared reports, and related backends encrypt data at rest under their own controls.

At rest (device)

Local capture files are not encrypted at rest by Pacific Machines. Protection relies on the operating-system user account and disk encryption (FileVault on macOS, BitLocker on Windows). Organizations that process regulated data should require disk encryption, MDM, and other endpoint controls in their own environment. That is a customer control, not something this app can enforce on the laptop.

Secure development and releases

We follow a documented secure-development and change-management approach: production changes are reviewed before they ship, and access to promote builds is limited to authorized people.

Desktop installers are published to the public GitHub repository reefo-inc/jarbas-releases. The website download routes and the in-app updater read the same production feed, so they cannot advertise different current versions. If the feed is unreachable, malformed, or missing a platform, the download route fails closed instead of linking a stale file.

Before a Mac build is promoted it is signed, notarized, stapled, and integrity-checked. Windows builds receive equivalent signature and integrity checks. Emergency kill switches can pause a platform's public download if a release should not be offered.

When an install is below the minimum required version, Pacific Machines blocks with a clear Update action that downloads and installs through the signed in-app updater on macOS and Windows, instead of sending users to a separate downloads folder.

Shipped product changes are listed on the public changelog.

Vendors and subprocessors

We use subprocessors for work we do not run ourselves. Written agreements with vendors that handle company or customer data include confidentiality and privacy commitments applicable to that relationship. Critical vendors are inventoried and reviewed as part of our third-party management policy.

CategoryExamples
IdentityClerk (authentication, organizations, billing)
Cloud dataConvex (Brain sync, shared team reports, and related org data)
InferenceLLM providers when a user sends Chat or Agent requests
PluginsComposio, only after the user connects a tool
WebsiteHosting (Vercel) and product analytics (PostHog)
ReleasesGitHub (public installer feed)

Connected plugins never replace measured screen capture. They run only for tasks you approve. A current description of what leaves the device is in the Privacy Policy.

People and endpoints

Human-resource security policy requires personnel to be suitable for their roles and to understand their security responsibilities. Employees acknowledge a code of conduct and confidentiality terms. Security awareness training is required as part of onboarding and on a recurring schedule.

Company endpoints used for production work are subject to our workstation and operations policies. We do not treat a customer's laptop as our managed estate: the customer controls disk encryption, MDM, and who may run Pacific Machines on that machine.

Incidents and vulnerability disclosure

We maintain a documented incident response plan, including a HIPAA addendum for potential ePHI incidents when that program applies. Security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties according to that plan, the applicable contract, and law. Customer-facing availability for Pacific Machines application and services is published on the public status page.

How to report a vulnerability

Email hans@pacificmachines.ai with:

  1. A short description of the issue
  2. Steps to reproduce, or a proof of concept that does not include customer data
  3. Impact as you understand it

Do not include secrets, PHI, passwords, or customer data in the first message. We will follow up on a tested channel.

Please do not probe, scan, or attack our systems or other users except with prior written authorization, as described in the Terms of Service.

Shared responsibility

Pacific Machines is used inside the customer's environment. We protect the service we operate. Customers protect the devices, accounts, and data they choose to put in front of the app.

We are responsible forCustomers are responsible for
Building and shipping the desktop app and related cloud servicesDeciding who may install and use the app
Account authentication and organization membershipStrong credentials and seat management
Encryption in transit to our cloud providersDisk encryption and endpoint security on user machines
Not mirroring the capture library by defaultLearning mode, ignore lists, cleanup, and pausing Learning
Documented incident response for our systemsConsents and lawful basis to capture what appears on screen
Vendor agreements for subprocessors we engagePlugins and tools they choose to connect

If you process PHI/ePHI, you must do so only under an appropriate agreement (such as a Business Associate Agreement) and with controls you implement in your environment.

Compliance status

Reefo, Inc. uses Vanta to operate and evidence its security program.

ProgramStatus
Information security policiesApproved and reviewed at least annually
SOC 2 Type IIIn process with Vanta; we expect to obtain SOC 2 in the coming weeks. Not certified today.
HIPAAInternal policies and BAA pathway exist. Not a HIPAA certification.

Customer-facing product description is on pacificmachines.ai. For diligence beyond this whitepaper, book a call or email hans@pacificmachines.ai.

Related public documents

  • Product documentation — user guide and FAQ
  • Changelog — public release notes
  • Status — public application status and incident communications
  • Privacy Policy — collection, storage, sharing, and user controls
  • Terms of Service — contractual terms, including security commitments

Security contact: hans@pacificmachines.ai

Reefo, Inc. · San Francisco, California · Whitepaper version 2026.09

Pacific Machines

Intelligent systems for consequential work.

Product

HomeDocsChangelogStatus

Legal

Privacy PolicySecurityTerms of Service

Contact

Book a call

© 2026 Reefo, Inc. Built in San Francisco.