Security architecture

Know where profile data and access live.

AliasMode separates browser profiles, makes Local and Cloud explicit modes, and gives Cloud workspaces device, version, concurrency, and deletion controls.

Profile isolation

Each profile has a persistent user-data directory with its own cookies, session state, extensions, proxy, user agent, screen values, and fingerprint seed.

Local boundary

Local mode requires no AliasMode account, sends no traffic to AliasMode Cloud, and keeps AliasMode profile data on that computer.

Cloud access

Cloud uses a verified email and password. Each account has one workspace with owner and member roles, and workspace devices can be revoked.

Synchronization controls

Cloud synchronizes encrypted portable profiles, keeps a local cache, rejects stale uploads, retries pending uploads, and warns about concurrent opens.

Deletion workflow

Cloud workspaces include trash for deleted profiles. Keep profile lifecycle and client offboarding steps clear for every operator.

Release integrity

The Windows beta publishes its release source and SHA-256 when an installer is available. The current beta is unsigned, so Windows can show SmartScreen.

Inspect the desktop client

Apache-2.0 source is public.

AliasMode is open source: the complete desktop app is Apache-2.0. CloakBrowser is a third-party engine included at no extra cost under its own license, and AliasMode Cloud is an optional managed service.

View the desktop source

Report a security issue

Send a responsible report to security@aliasmode.com. Include the affected component, version, reproduction steps, and expected impact.