Skip to content
cloudroom

Security

Your agents get real access to your code and logins. Cloudroom is built to keep that access contained.

How we protect your work

  • Each cloud thread runs in its own isolated sandbox. Sandboxes are never shared between threads or users.
  • Agents get full admin rights inside their own sandbox, but no access to other sandboxes.
  • The access token Cloudroom keeps in a sandbox only works for that one sandbox.
  • Every request to your core needs a secret 256-bit token. The desktop app only connects to remote cores over HTTPS.
  • Session history is saved outside the sandbox, over an encrypted connection with full certificate checks.
  • Your agents call your model providers directly, with your own logins. Cloudroom never sits in between.
  • When an agent needs an API key, you enter it in a secure form. The key never appears in the chat, history, or logs.
  • Command Guard, on by default, stops a few catastrophic commands before they run, such as deleting your home folder, formatting a disk, or deleting a GitHub repository.
  • The Cloudroom core is open source under Apache 2.0, so anyone can audit it.

Know the limits

  • Agents run without approval prompts. With admin rights, they can read anything in their sandbox, including the keys Cloudroom keeps there.
  • Subagents share their thread’s sandbox, so they can change each other’s files.
  • With Mac access on, cloud agents can read files and run commands on your Mac as you. You can turn it off anytime in Settings.
  • Command Guard only catches a few known commands, and you can turn it off in Settings.

Report a vulnerability

Email david@davidondrej.com or report it privately on GitHub. Please do not open public issues for security problems.