Security
Agents execute code on your machines. The platform is designed around that: credentials stay on workers, commands are never shell strings, destructive Git is refused, and every organization is isolated.
Architecture
The whole platform can run inside your network, with no calls to vendor infrastructure.
Outbound-only workers
Workers connect out to the control plane; their local UI binds to 127.0.0.1 with a per-worker token and rejects DNS rebinding.
Project isolation
Agents run only inside mapped project folders; path traversal and symlink escapes are rejected.
Credentials and secrets
OS credential stores
Worker credentials, agent and provider keys live in Windows Credential Manager, macOS Keychain or the Linux Secret Service.
Encryption at rest
Organization secrets and two-factor secrets are encrypted with AES-256-GCM; the key can be rotated.
Masked and redacted
Secrets are only ever shown masked and are redacted from logs, events, errors and verification output.
Allow-listed environments
Agents get an allow-listed environment plus the selected provider credential — not the worker’s other secrets.
Audited delivery
Secrets for a task’s environment are sent only for that task, and each delivery is audited by name.
Signed worker updates
Workers install only releases signed with a key they trust; a compromised server cannot push code.
Access
Sign-in
scrypt password hashing, lockout, timing-safe responses, OIDC with PKCE and verified ID tokens, TOTP two-factor.
RBAC
Five roles enforced in the service layer on every operation; users cannot grant roles above their own.
Tenant isolation
Organization ids come from verified membership; every query is scoped; non-members get 404. Tested with cross-organization attempts.
Sessions
Short-lived access tokens, rotating refresh tokens with reuse detection, SameSite=Strict cookies plus a custom header against CSRF.
Web hardening
Security headers and CSP, a CORS allow-list and rate limits — stricter on sign-in routes.
Audit log
Append-only: update and delete are blocked at the model layer.
Execution
No shell interpolation
Commands are argument arrays with shell disabled; Windows .cmd shims are validated; prompts go through stdin or files.
Safe Git
Force-push, reset --hard, clean, branch deletion and discarding changes are refused; your uncommitted work is never committed.
Capability permissions
Capabilities declare permissions; policies block or require approval for risky ones such as shell, secrets and browser control.
Isolated plugins
Plugins run in separate Node.js processes with only their declared permissions, no inherited environment, and time and memory limits.
MCP health checks
Servers are checked before an agent receives them; failing ones are left out.
OS sandbox
Optional bubblewrap (Linux) or sandbox-exec (macOS) sandbox for agents.
Known gaps
Certifications
Reporting a vulnerability