Product policy
Safety & security
Separate observation, advice and permission to act.
Local safety
The current monitor is advisory. Process identity, ownership, foreground state, activity, protected groups and reserves are evaluated locally. Missing evidence blocks action; size alone is never permission.
Optional remote advice
Aggregate-only inputs and enum-only outputs prevent the adviser from issuing commands or process targets. Jobs are isolated, with quotas, timeouts and conservative budget reservations.
Protected operation
The backoffice requires authentication and administrator authorization. Mutations require CSRF protection and the correct origin. Secure cookies, bounded inputs and rate limits protect the HTTPS surface. Secrets remain server-side; the API does not receive the OpenAI runtime key.
Release gates
Native signing, OS credential-vault storage, platform acceptance and measured disposable-workload recovery remain required before commercial installers or automatic actions.
Report a concern
Use the support form and select Security. Describe the issue without publishing exploit payloads, credentials or private customer data. No bounty or response-time guarantee is offered.
Keep your work flowing.
Explore the product, read the guides and check release availability.