Feature · Built for Mac
Egress log
Complete network visibility with zero hidden background telemetry.
What this helps you achieve
- Inspect real-time request timestamps, target domains, and payload sizes
- Zero mystery network packets or unverified background telemetry
- Exportable JSON audit logs for enterprise security compliance reviews
Modern software applications are notorious for running opaque network traffic. Open Activity Monitor on macOS, and you will discover dozens of background helper services exchanging megabytes of data with servers across the globe.
Even when software vendors promise privacy in marketing brochures, users are left with no practical way to audit what is leaving their machine without setting up complex packet interception proxies.
Oyma believes that true privacy requires radical transparency. Implemented in src/renderer/privacy/egress-log.ts, Oyma features an integrated Egress Log—an auditable, real-time ledger that records every single outbound network request initiated by the application.
A live, auditable window into network behavior
The Egress Log transforms network activity from a hidden background mystery into a clear, visible ledger accessible directly inside the application interface.
Whenever Oyma communicates over a network adapter:
- Deterministic capture: The internal network dispatch pipeline intercepts the request before socket transmission begins.
- Metadata extraction: The log records the ISO timestamp, target domain name, full URL path, HTTP method (
GET,POST), and exact request payload size in bytes. - Response metrics: Upon completion, the log records the HTTP response code (
200 OK,401 Unauthorized), round-trip latency in milliseconds, and received byte count. - Instant UI reflection: The entry appears immediately in the Settings > Privacy & Network ledger table, complete with color-coded status badges.
If an unexpected request ever occurs, you see it instantly. There are no dark corners and no hidden telemetry streams.
What you see in the log: Radical absence
The most remarkable feature of the Oyma Egress Log is how frequently it displays nothing at all:
- Zero-bot call recording: Record a 2-hour executive strategy call with meeting recording without a bot; the egress log records zero requests.
- On-device speech transcription: Transcribe an entire keynote lecture using live Whisper transcription; the log remains completely empty.
- Local AI summarization: Generate executive summaries and action matrices using local AI with Ollama; because Ollama runs over the local loopback interface, zero external egress entries are recorded.
- Markdown note editing: Author, link, and format documentation in the live-preview editor; zero network events occur.
The only requests that ever appear in the Egress Log are those you have explicitly configured and authorized:
- Cloud LLM requests: Direct calls to
api.anthropic.comorapi.openai.comwhen utilizing our bring your own key integration. - Web link card previews: Lightweight
GETrequests to retrieve Open Graph metadata when pasting external URLs into notes. - Application update checks: Checking our signed update feed for new desktop application releases.
If you activate local-only mode, even these optional endpoints are blocked immediately.
Enterprise auditability and export capabilities
Corporate information security teams and compliance officers must verify software integrity before approving deployment across enterprise fleets.
The Egress Log is engineered to satisfy strict enterprise audit requirements:
- One-click JSON export: Security engineers can export the complete network ledger formatted as structured JSON for ingestion into enterprise SIEM (Security Information and Event Management) platforms.
- Deterministic provenance: Each log entry records the internal subsystem identifier that initiated the call, eliminating ambiguity regarding which feature requested network access.
- Tamper-resistant local storage: The in-memory audit ring buffer operates with bounded size constraints, preventing memory exhaustion while preserving recent operational history.
Protocol inspection and anomaly alerting
Beyond listing outgoing requests, the Egress Log equips users with analytical tools to detect unauthorized behavioral anomalies:
- Protocol and cipher suite verification: Inspect the TLS version and certificate authority for every external connection to verify that secure encryption standards are upheld.
- Payload size monitoring: Visual warning indicators flag any transmission exceeding 100 kilobytes, allowing you to catch accidental bulk uploads before completion.
- Filter by subsystem: Quickly isolate network events generated by cloud AI providers from basic update feed queries using dedicated category filters.
- Configurable retention windows: Choose whether network logs persist for 24 hours, 7 days, or flush automatically upon application termination. Security-conscious users can clear the ledger immediately with a single reset button without restarting the application.
Verification over blind trust
In an era of ubiquitous cloud monitoring and intrusive session-replay scripts, Oyma provides a refreshing commitment to verifiable user sovereignty.
You do not have to accept corporate privacy promises on faith. With the Egress Log, you hold the audit tools directly in your hands.
Pair complete network visibility with local plain text file storage in our comprehensive privacy architecture and experience private computing built for serious professionals.
Questions
Related: Markdown basics, vault compatibility, and free browser tools.
Where can I view the Egress Log inside Oyma?
Open Settings > Privacy & Network to view the live Egress Log table, showing real-time timestamps, destination hosts, protocols, and transfer sizes.
What requests appear in the Egress Log during standard usage?
Under default local-only usage with Ollama, the log remains completely empty. If you configure BYOK cloud AI or open web link cards, those explicit calls appear.
Can I export the network audit ledger for external compliance verification?
Yes. You can export the complete chronological egress log as a structured JSON file with a single click for security team review.
Does Oyma log the actual prompt text or note content in the egress log?
No. The egress log records metadata—destination URL, timestamp, HTTP method, and byte payload length—without saving private note contents to log files.
Your notes, in plain Markdown.
Free during the private beta. Apple silicon Macs, macOS 14 or later.