LLM Proxy Security Model
How the local proxy intercepts LLM traffic and what data is stored.
What the proxy is
Iria Monitor includes an optional local proxy powered by mitmproxy (mitmproxy.org). It runs entirely on your machine and intercepts HTTPS traffic between your AI coding assistants (Claude Code, Cursor, Copilot, Codex) and their API providers.
How TLS interception works
The proxy generates a local Certificate Authority (CA) stored at ~/.mitmproxy/. When trusted by your system, this CA allows the proxy to terminate TLS connections on localhost only. Traffic is decrypted in memory, usage metrics are extracted, and the request is re-encrypted and forwarded to the upstream API. This is a standard MITM (Machine-In-The-Middle) proxy pattern — the same technique used by corporate firewalls, debugging tools like Charles Proxy, and mitmproxy itself.
What data is captured
The proxy extracts only usage metrics from API responses:
- Model name (e.g. claude-sonnet-4-6, gpt-4o)
- Token counts (input, output, cache read/write)
- Estimated cost in USD
- Git context: repository name, branch, and git user
- Process name and session identifier
What is NOT stored
The following data transits through the proxy process in memory but is never written to disk:
- API keys, OAuth tokens, or any authentication credentials
- Full prompt text or system instructions
- Full model responses or generated code
- Request or response bodies beyond extracted metrics
File locations and permissions
All files are created with chmod 600 (owner-only read/write):
~/.iria/proxy_events.jsonl— captured usage events (JSONL)~/.mitmproxy/mitmproxy-ca.pem— CA private key (should be 600)~/.mitmproxy/mitmproxy-ca-cert.pem— CA public certificate~/.iria/proxy_config.json— proxy configuration~/.iria/proxy/— per-session request metadata: model, token counts, timing and status only, never prompt or response content
CA certificate lifecycle
The CA certificate is generated by mitmproxy on first run. You must explicitly trust it in your system keychain for the proxy to work. On uninstall (iria-monitor proxy disable), the launchd agent is removed. To fully revoke trust, remove the certificate from your system keychain and delete ~/.mitmproxy/.
How to disable
Disable the proxy at any time:
iria-monitor proxy disableThis stops the background proxy process and removes the launchd agent. Your AI tools will connect directly to their APIs without interception.