Documentation menu
Operate / v0.1

Support and escalation

Who is responsible for what, how to escalate, the release inventory, known gaps and the controls that stay in place.

Reviewed September 27, 2026 · Current implementation

What Recursift does not provide

Who is responsible for what

AreaRecursiftYou
Endpoint softwareBuilds, signs and publishes the Mac installer, updates and release notesInstalls, enrolls, applies updates, uninstalls
Hosted servicesOperates the console, Query API, MCP service and update hostManages console sign-in, endpoint enrollment and revocation
Collection and postureProvides policy, profiles and gold buildsSets policy, reviews acknowledgements and comparisons
MonitoringNoneReviews presence, events, findings and detection results
Incident responseNoneDecides and acts with your own process and tools
Local evidenceNo key escrow; cannot recover lost keysKeeps the Mac and its keychain healthy; backs up what you need
API keysIssues and revokes customer API keys on requestStores keys securely and asks for revocation when needed

How to escalate

1. Run the read-only checks in Triage health and incidents. 2. Collect the agent version, the status output, the last 100 lines of the agent log, the console agent ID, any question or job ID, and the time you saw the problem. Never send enrollment tokens, API keys or raw evidence. 3. Write to hello@recursift.com with a short description of what you expected and what happened.

For a suspected compromise, start your own incident process first. Recursift can explain what the product observed and how to read it; it is not your responder.

Response expectations

Support is best effort. There is no service-level agreement, no guaranteed response or resolution time, and no on-call coverage.

Release inventory

ComponentVersionSource commitSupported profile
Endpoint agent and Mac installer0.2.4 (September 26, 2026)agent d106bd0Mac with Apple silicon, observe-only
Console at recursift.appNo version numberwebapp cfb115fCurrent browsers
Query API and MCP service0.1.0api 6d23a5eServer-side integrations with a customer key
Developer documentationv0.1This siteReviewed September 27, 2026

Commits are the main branches reviewed on September 27, 2026. Check the installed agent with recursift-agent version.

Known gaps

AreaGap
PlatformsWindows, Linux and Intel Macs are not supported. No minimum macOS version is published.
InstallationNo uninstaller. The console's enroll command omits the installed path and state folder. Local questions and profiles from Terminal need extra configuration.
CoverageProcess activity between polls can be missed; process-creation events are not collected. File scans report Unavailable on a standard installation.
ConsoleNo alerts or notifications, no incident timeline, and no acknowledgment, assignment or closure of findings. No detection exceptions.
ResponseObserve-only. Isolation, process and file actions are refused.
UpdatesNo centrally managed updates, version policy, gradual rollout or rollback.
RetentionNo console retention period or endpoint deletion; no bound on local audit segments.
RecoveryNo evidence key escrow. Whole-folder deletion or rollback by a privileged user is not detected.
ReliabilityRestart, load, offline and update reliability have not been measured.
SupportBest effort only; no SLA, on-call or staffed monitoring.

Controls that stay in place

ControlWhat it means
Observe-onlyEnforcement mode refuses to start. Would-be actions are recorded, never executed.
Policy cannot grant powerCollection policy cannot enable enforcement or change the endpoint's action gate.
Peer evidencePeer evidence raises priority, never authorizes action.
Fixed read-only questionsQuestions run only fixed read-only checks with bounded arguments; they cannot run arbitrary queries.
Sealed local evidenceLocal evidence is sealed with keys held in the Mac's keychain. There is no unsealed fallback.
One-time enrollmentTokens work once and expire after 24 hours. Endpoint keys can be revoked at any time.
Signed findings and configurationThe console verifies signed findings; the endpoint rejects unsigned or mismatched configuration and keeps the previous one.
Customer isolationAPI keys are scoped to one customer, expire and can be revoked. Browser-origin API calls are refused.
Continue readingDeployment profiles →