Inspect network requests with the Egress log
Trust in a privacy-focused notes app should be verifiable through empirical evidence, not blind faith or marketing promises. Oyma includes a built-in, real-time Egress log that records every network socket connection and HTTP request initiated by the application.
Whether you work in a regulated legal practice, handle privileged medical records, manage enterprise financial audits, or simply demand that your meeting recordings remain private, the Egress log allows you to independently verify and audit all network activity on your Mac.
Why client-side network auditing matters
Traditional cloud productivity apps hide their network activity behind minified JavaScript bundles and background syncing daemons. A typical cloud notes tool contacts dozens of third-party domains every hour for telemetry, crash trackers, ad retargeting pixels, and database replication.
Oyma takes an inverted, transparent approach:
| Dimension / Behavior | Typical Cloud Note App | Oyma Native Architecture |
|---|---|---|
| Outbound Analytics | 10–25 third-party tracking SDKs | Zero tracking SDKs or behavioral analytics |
| Meeting Audio Routing | Uploaded to remote transcription servers | Processed 100% locally on Apple Silicon |
| Telemetry Payloads | Background heartbeat every 30–60 seconds | Completely silent; zero background pings |
| In-app Network Audit | Hidden; blocked from inspection | Full real-time ledger visible to the user |
| Audit Log Export | Not supported | One-click JSON or CSV cryptographic export |
| Offline Hard Enforcement | App breaks or degrades without cloud | Full offline operation with physical socket killswitch |
How the Egress log captures network events
The Egress log operates at the lowest networking abstraction layer of the application runtime:
- Main process interception: Electron’s
session.defaultSession.webRequestsubsystem intercepts all renderer HTTP and WebSocket requests before they reach the OS networking stack. - Node runtime socket hooks: Low-level
http.requestandhttps.requestmodules are wrapped with non-blocking diagnostic probes. - Loopback detection: Network destinations resolving to
127.0.0.1,::1, orlocalhostare flagged asLocal (Loopback)so you can easily distinguish local AI queries from true internet requests.
How to open and use the Egress log
You can open the network ledger at any time:
- Press ⌘O to open the Command Palette.
- Type
>Open Egress logand press Enter. Alternatively, go to Settings (⌘,) → Privacy → View Egress Log. - A floating diagnostic window appears showing real-time network traffic.
Ledger schema and column definitions
The Egress log provides rich diagnostic metadata for each connection:
- Timestamp: Precise millisecond timestamp (
YYYY-MM-DD HH:mm:ss.SSS). - Origin Process: Identifies whether the call originated from the
Main Process(e.g., auto-update checks) or theRenderer Process(e.g., BYOK API calls). - Destination: Target hostname and port (e.g.,
api.anthropic.com:443or127.0.0.1:11434). - Method & Path: HTTP verb and endpoint path (e.g.,
POST /v1/messages). - Bytes Sent / Received: Exact byte-level tally of transmitted and received data packets.
- TLS Version: Encryption cipher suite and protocol (e.g., TLS 1.3).
- Status & Policy: Displays HTTP status code (
200 OK,401 Unauthorized) or enforcement outcome (ALLOWEDvsBLOCKED_BY_LOCAL_MODE).
What normal activity looks like in Oyma
When using Oyma throughout a standard workday, here is what you will observe in the Egress log:
1. Taking notes and searching
- Ledger state: Completely blank. Zero entries are generated.
- Explanation: Note creation, Markdown parsing, graph rendering, and SQLite FTS5 search run entirely inside local memory and disk storage.
2. Live meeting recording and transcription
- Ledger state: Completely blank. Zero entries are generated.
- Explanation: Audio capture uses native macOS CoreAudio APIs. Transcription runs on your Mac’s Apple Silicon Neural Engine using embedded Whisper models. Zero audio bytes touch your network card.
3. Local AI summaries with Ollama
- Ledger state: Entries show
127.0.0.1:11434with statusLOCAL_LOOPBACK. - Explanation: Communication with Ollama occurs over local loopback interfaces. No data traverses external routers or the public internet.
4. Cloud AI summaries using your own API keys
- Ledger state: Single HTTPS
POSTtoapi.anthropic.comorapi.openai.com. - Explanation: Shows the exact byte payload of the meeting transcript sent and the summary received.
5. Application update checks
- Ledger state: Occasional lightweight
GETtoupdates.getoyma.com(disabled if Local-only mode is active).
Exporting audit reports for security compliance
For enterprise teams, HIPAA compliance officers, or security evaluations, Oyma allows you to export verified network records:
- In the Egress log window, click Export Audit Ledger….
- Choose your format:
- JSON Ledger: Machine-readable JSON array with timestamps, destinations, byte counters, and cryptographic checksums.
- CSV Ledger: Tabular data ready for Excel or enterprise SIEM log ingestion.
- Select a destination folder in your vault.
The export automatically sanitizes any sensitive Authorization headers while preserving byte volumes and endpoint verification.
Enforcing a physical network killswitch
If your threat model requires absolute certainty that zero outbound packets can leave the application under any circumstances, combine the Egress log with Local-only mode. Local-only mode physically severs all non-loopback networking sockets at the runtime level. Any outbound network call is immediately rejected and recorded in the Egress log as BLOCKED_BY_POLICY.
To learn more about how Oyma isolates notes and media locally, read our comprehensive privacy architecture and guide to on-device AI with Ollama.
Questions
What is the Egress log in Oyma?
The Egress log is an auditable network ledger built directly into Oyma that records every outbound network connection attempt from both the main process and renderer window, complete with timestamps, hostnames, and byte counters.
Does Oyma send background telemetry or analytics?
No. Oyma includes zero third-party telemetry, tracking SDKs, or session-recording tools. Telemetry is opt-in, disabled by default, and reports only anonymized crash logs if explicitly enabled.
Can I export the Egress log for security audits?
Yes. You can export the complete network ledger as a JSON audit file or plain text log to inspect with enterprise network monitoring tools.
What outbound requests appear when using Ollama?
Zero external requests. Ollama communicates strictly over local loopback (127.0.0.1:11434). Requests to loopback addresses are marked as local in the Egress log and never touch your physical network adapter.
Does the Egress log intercept raw HTTPS payloads?
For security and privacy, the Egress log audits hostnames, endpoints, headers, and exact byte volume transferred without exposing raw API tokens or sensitive private body payloads in audit exports.