Security
Trust rules
Nobody should run an unknown program on a production server unless these rules hold. They are part of the product, and no feature is worth breaking one.
Rules for the agent
Section titled “Rules for the agent”1. Read-only
Section titled “1. Read-only”It never changes a file, a setting or a container. It prints the fix, and you run it.
2. Open source
Section titled “2. Open source”The agent’s code is published at release, so anyone can read what it does before installing it. Until then, what the agent reads and sends lists every file it reads and everything it sends.
3. Local by default
Section titled “3. Local by default”A one-off scan sends nothing off the server. Data leaves only after you connect the server, which a later release adds.
4. Secrets never leave
Section titled “4. Secrets never leave”The agent reports that a secret exists and where, never its value. Passwords in logs and connection settings are masked on the server.
5. Outgoing only
Section titled “5. Outgoing only”The agent opens no port and accepts no incoming connection.
6. Easy to remove
Section titled “6. Easy to remove”One command uninstalls it. One click deletes a server’s history.
7. No AI and no third parties
Section titled “7. No AI and no third parties”Logs, errors and findings go only to the service’s own storage.
Rules for the service
Section titled “Rules for the service”These hold for the hosted dashboard when it arrives.
- Two-step sign-in is required for every teammate, in the dashboard and in the terminal.
- Each token does one job. A server token can only send results. A deploy token can only mark deploys. Neither can read data.
- Every action is recorded in the activity log: who assigned, muted, invited or changed what.
- Every request is checked against the person’s role and access, on the server. Anything hidden from them answers as not found.
See for yourself
Section titled “See for yourself”What the agent reads and sends lists every file and setting a scan reads. It is built from the same file the agent uses.