Skip to content
Iria Monitor

LLM Proxy Security Model

How the local proxy intercepts LLM traffic and what data is stored.

What the proxy is

Iria Monitor includes an optional local proxy powered by mitmproxy (mitmproxy.org). It runs entirely on your machine and intercepts HTTPS traffic between your AI coding assistants (Claude Code, Cursor, Copilot, Codex) and their API providers.

How TLS interception works

The proxy generates a local Certificate Authority (CA) stored at ~/.mitmproxy/. When trusted by your system, this CA allows the proxy to terminate TLS connections on localhost only. Traffic is decrypted in memory, usage metrics are extracted, and the request is re-encrypted and forwarded to the upstream API. This is a standard MITM (Machine-In-The-Middle) proxy pattern — the same technique used by corporate firewalls, debugging tools like Charles Proxy, and mitmproxy itself.

What data is captured

The proxy extracts only usage metrics from API responses:

  • Model name (e.g. claude-sonnet-4-6, gpt-4o)
  • Token counts (input, output, cache read/write)
  • Estimated cost in USD
  • Git context: repository name, branch, and git user
  • Process name and session identifier

What is NOT stored

The following data transits through the proxy process in memory but is never written to disk:

  • API keys, OAuth tokens, or any authentication credentials
  • Full prompt text or system instructions
  • Full model responses or generated code
  • Request or response bodies beyond extracted metrics

File locations and permissions

All files are created with chmod 600 (owner-only read/write):

  • ~/.iria/proxy_events.jsonl — captured usage events (JSONL)
  • ~/.mitmproxy/mitmproxy-ca.pem — CA private key (should be 600)
  • ~/.mitmproxy/mitmproxy-ca-cert.pem — CA public certificate
  • ~/.iria/proxy_config.json — proxy configuration
  • ~/.iria/proxy/ — per-session request metadata: model, token counts, timing and status only, never prompt or response content

CA certificate lifecycle

The CA certificate is generated by mitmproxy on first run. You must explicitly trust it in your system keychain for the proxy to work. On uninstall (iria-monitor proxy disable), the launchd agent is removed. To fully revoke trust, remove the certificate from your system keychain and delete ~/.mitmproxy/.

How to disable

Disable the proxy at any time:

iria-monitor proxy disable

This stops the background proxy process and removes the launchd agent. Your AI tools will connect directly to their APIs without interception.