Security
Your agents get real access to your code and logins. Cloudroom is built to keep that access contained.
How we protect your work
- Each cloud thread runs in its own isolated sandbox. Sandboxes are never shared between threads or users.
- Agents get full admin rights inside their own sandbox, but no access to other sandboxes.
- The access token Cloudroom keeps in a sandbox only works for that one sandbox.
- Every request to your core needs a secret 256-bit token. The desktop app only connects to remote cores over HTTPS.
- Session history is saved outside the sandbox, over an encrypted connection with full certificate checks.
- Your agents call your model providers directly, with your own logins. Cloudroom never sits in between.
- When an agent needs an API key, you enter it in a secure form. The key never appears in the chat, history, or logs.
- Command Guard, on by default, stops a few catastrophic commands before they run, such as deleting your home folder, formatting a disk, or deleting a GitHub repository.
- The Cloudroom core is open source under Apache 2.0, so anyone can audit it.
Know the limits
- Agents run without approval prompts. With admin rights, they can read anything in their sandbox, including the keys Cloudroom keeps there.
- Subagents share their thread’s sandbox, so they can change each other’s files.
- With Mac access on, cloud agents can read files and run commands on your Mac as you. You can turn it off anytime in Settings.
- Command Guard only catches a few known commands, and you can turn it off in Settings.
Report a vulnerability
Email david@davidondrej.com or report it privately on GitHub. Please do not open public issues for security problems.