Homeport topology

Homeport topology An architecture diagram generated by Archify. Your devices · iOS · Android · laptop · agent · Architecture component Your devices iOS · Android · laptop · agent tailscale serve · HTTPS · identity headers · Your always-on Mac tailscale serve HTTPS · identity headers Loopback listener · 127.0.0.1 · policy.json scopes · Your always-on Mac › 127.0.0.1 only Loopback listener 127.0.0.1 · policy.json scopes MCPServer · 39 tools · one serial queue · Your always-on Mac MCPServer 39 tools · one serial queue respondTool · note guard · audit · envelope · Your always-on Mac respondTool note guard · audit · envelope Local MCP client · same Mac · stdio · Your always-on Mac Local MCP client same Mac · stdio EventKit · Calendar · Reminders · Your always-on Mac EventKit Calendar · Reminders Contacts · CNContactStore · Your always-on Mac Contacts CNContactStore Notes · in-process Apple Events · Your always-on Mac Notes in-process Apple Events Messages · chat.db copy · send allowlist · Your always-on Mac Messages chat.db copy · send allowlist Voice Memos · Shortcuts · on-device Speech · shortcuts CLI · Your always-on Mac Voice Memos · Shortcuts on-device Speech · shortcuts CLI Local model · OpenAI-compatible · optional · Architecture component Local model OpenAI-compatible · optional WireGuard identity in scope stdio route · summarize result or error response Your always-on Mac 127.0.0.1 only

Reach

  • • Any device on your tailnet, over WireGuard
  • • Nothing on the public internet, no API keys
  • • Local clients speak stdio and skip the network

Guards

  • • Identity from tailscale serve, scopes from policy.json
  • • Every result and error leaves through respondTool
  • • Messages only go to handles you enrolled

Stays on your Mac

  • • One signed binary owns every privacy grant
  • • Speech runs on-device
  • • Summaries use a local model, if you add one