v2.2.0
Security & Transparency Reference

How Hermes Go Works

A transparent breakdown of the privacy model, network boundaries, update verification, credential handling, and open-source relationships in Hermes Go.

Direct WSS

Direct peer connection. No relay cloud.

Zero Telemetry

No tracking or analytics SDKs.

Signed OTA

Runtime-locked bundle validation.

Hardware Keystore

Android SecureStore encryption.

System Architecture & Transport

Direct client-to-agent peer communication model
Direct WSS

Hermes Go is a native mobile interface designed specifically to control a self-hosted Hermes Agent instance. It does not operate any central cloud databases, routing proxies, or traffic-intercepting relays.

Hermes Go

Android Client
Edge UI
  • React Native Native UI
  • Hardware SecureStore Keystore
  • Local Appearance & Cache
  • Zero Cloud Telemetry
WSS / JSON-RPC
Point-to-Point Transport
LAN · Tailscale · HTTPS

Hermes Agent

Host Daemon
Core Engine
  • System Tools, Shell & Skills
  • SQLite Sessions & Memory DB
  • LLM Provider & Model Gateway
  • Multi-Agent Bots Engine

All conversation turns, tool streaming outputs, system control operations, and cron jobs run on your host. The mobile client parses and renders incoming JSON-RPC streaming frames over a persistent WebSocket and dispatches user prompts directly to the agent runtime.

Network Data Flows

Complete catalog of every outbound network request
4 Destinations Only

Hermes Go makes network requests to exactly four distinct destinations. There are no silent or undeclared network calls:

Destination Payload Data Operational Purpose Frequency
Your Hermes Server
LAN / Tailscale / Cloud
Prompts, tool arguments, approval responses, session queries Core agent operations, real-time message streaming, system control Active user sessions & background task monitoring
Expo Update CDN
u.expo.dev
App runtime version string & release channel Checks if an updated JavaScript bundle is available for the installed build On app launch & manual refresh
GitHub API
api.github.com
Anonymous request — no account, token, or device data sent Anonymous commit-distance check for the hermes-agent pin — how far the app's tested build trails latest main (cached for 6 hours) When the agent-update notice is opened
Your LLM Providers
openrouter.ai · api.deepseek.com · api.z.ai · api.novita.ai · open.bigmodel.cn · api.minimax.io · api.moonshot.cn · api.kimi.com · ollama.com · opencode.ai · api.commandcode.ai
The provider API key already stored on your server, revealed to the app for this check only and held in memory — never saved to disk or logs Reads remaining quota / balance so the Provider quota cards can display it (some windows, such as Codex and Claude, are computed by your own server instead) Only when you open or refresh a quota sheet; off via Settings → Hermes Go features → Providers, which clears the keys from memory
Supabase Edge Functions
*.supabase.co/functions/v1/
User feedback text, category, optional anonymous device token Transmits voluntary bug reports and loads public changelog / feature catalog Only on explicit feedback submit or opening changelog

If your Hermes server is offline or disconnected, Hermes Go cannot communicate with any fallback servers, because no intermediate cloud backend exists.

Over-The-Air (OTA) Updates & Integrity

How JavaScript updates work without compromising native security
Runtime-Locked

Hermes Go uses Expo's modern EAS Update mechanism to deliver rapid bug fixes and UI enhancements directly without requiring users to download a new build from Google Play for every patch.

  • What updates over the air: UI components, state management logic, stylesheets, theme presets, and client-side formatting.
  • What NEVER updates over the air: Native C++/Kotlin binary code, Android manifest definitions, requested OS permissions, or native SDK modules.
Strict Runtime Version Guard: Every OTA bundle is cryptographically tied to the exact native fingerprint of the distributed APK. If a bundle is signed for a different runtime fingerprint, the Android client immediately rejects it and continues running the local bundle. Any native change mandates a brand new Google Play release.

Supabase Edge Integration Boundaries

Strict separation between feedback storage and application data
Public Endpoints Only

The mobile app connects to specific serverless Edge Functions hosted on Supabase for three public utility functions:

Function Endpoint Data Sent Authentication Required
/functions/v1/feedback User-submitted issue description, category (bug/feature), optional screenshot Anonymous device UUID (generated on first run, stored in SecureStore)
/functions/v1/feature-map None (HTTP GET request) None (Public catalog query)
/functions/v1/changelog None (HTTP GET request) None (Public version notes query)

Explicit non-goals: Supabase is never used as an authentication provider, never stores your conversation transcripts, never receives memory entries, and does not record connection URLs or agent access tokens. No Supabase service-role keys are compiled into the client.

Credentials & Secrets Storage

Hardware-backed Android SecureStore encryption
Hardware Keystore

Sensitive parameters are isolated using Android's hardware-backed KeyStore and EncryptedSharedPreferences (via Expo SecureStore):

Secret Type On-Device Storage Location Transmission Target
Gateway Auth Cookie / Token Android SecureStore (encrypted at rest) Sent only to your configured Hermes server
WebSocket Ticket Ephemeral memory (single-use ticket) Exchanged during handshake, immediately expired
Custom Provider API Keys Never stored on phone. Managed on your server daemon. Client sends tri-state wire directive; server stores the secret

Credentials and tokens are stripped from logs and cannot be inspected or exfiltrated by secondary tools.

Android Operating System Permissions

Transparent mapping of device capabilities
Least Privilege

Every permission declared in Hermes Go maps strictly to an active, user-initiated feature:

Permission Associated In-App Feature Behavior & Trigger
android.permission.INTERNET Server Connectivity & Update Checks Establishes WebSocket and HTTP connections to your agent server, plus the throttled anonymous GitHub release check for update detection.
android.permission.RECORD_AUDIO Voice & Dictation Activated only when holding or tapping the microphone button in composer.
android.permission.CAMERA Image Attachments Requested only when you choose to take a real-time photo to send to the agent.
android.permission.READ_MEDIA_* File & Image Upload Invoked when selecting an image or document from your device gallery.
android.permission.FOREGROUND_SERVICE Background Reliability (Hermes Live) Maintains active agent streaming sessions during long-running tasks.
android.permission.FOREGROUND_SERVICE_REMOTE_MESSAGING Background Reliability (Hermes Live) Foreground service type that keeps streaming alive without the Android 15 6-hour runtime cap.
android.permission.WAKE_LOCK Background Reliability (Hermes Live) Prevents CPU suspension while a turn streams with the screen off, keeping the heartbeat alive.
android.permission.POST_NOTIFICATIONS Live Notifications Shows completed-turn alerts, blocking approval prompts, and bot chat updates — delivered locally, no push service.

Hermes Go does not request background location, contacts, calendar, SMS, or telephony permissions. All notifications are generated on-device — there is no Firebase Cloud Messaging or any third-party push relay.

The Self-Hosted Security Model

Your hardware owns the data, memory, and execution environment
100% Self-Contained

Because Hermes Agent is self-hosted on your machine, your security perimeter remains entirely under your control:

  • Session History: Stored in your host's local SQLite database.
  • Memories & Skills: Maintained within your server's local storage directory.
  • Workspace Files & Artifacts: Kept on your computer's filesystem.

Open Source & Licensing Relationships

Clear delineation between open-source projects and the mobile binary
Auditable Core

We maintain full transparency regarding the licensing of each layer in the ecosystem:

Ecosystem Component Licensing Status Source & Repository
Hermes Agent (Backend Daemon) Open Source · MIT License NousResearch/hermes-agent
Hermes Go Landing Site & App Map Open Source · MIT License shilp26/hermes-go
Hermes Go Android App Closed Source · Distributed via Google Play Independent mobile client compiled for Android arm64
Blobatar Generative Avatar Engine Open Source · MIT License Alain00/blobatar

The backend agent which holds broad execution capabilities is fully open-source and auditable. Hermes Go acts as a lightweight interface client to communicate with that agent over your secure network.

Binary Signing & Distribution

How release integrity is enforced end to end
Play-Signed

Hermes Go is distributed exclusively through Google Play, so every release reaches your device through a channel that verifies the publisher signature and the integrity of the package before it installs. There is no third-party download mirror and no APK file to check by hand.

You can confirm the listing yourself:

Where to verify: Google Play shows the publisher, the current version, and the app's data-safety declarations on the listing page. On device, Play Protect re-checks the installed app and flags anything that no longer matches what was signed.

Open the Google Play listing

Zero Telemetry Guarantee

Explicit list of excluded third-party frameworks and tracking SDKs
Guaranteed Zero

To be unequivocal, Hermes Go does not contain:

  • No third-party analytics: No Google Analytics, Firebase Analytics, Amplitude, Mixpanel, Segment, or PostHog.
  • No crash logging to commercial services: No Sentry, Crashlytics, or Bugsnag collecting stack traces with device context.
  • No advertising or monetization SDKs: No ad banners, interstitials, affiliate injectors, or tracking pixels.
  • No mandatory cloud registration: No user accounts, passwords, or registration forms to use the client.
  • No data brokerage: Zero data sharing, selling, or monetization of telemetry.