Set boundaries before adding capability

A clear split between control and SSH data planes

Connections remain direct end to end; the cloud accepts only classified, explicitly allowed data.

Connections and host safety

Important changes stay visible and unfamiliar resources are never modified automatically.

SSH

Local tunnel

The client initiates the connection and the agent exposes no public port.

Minimal exposure
Identity

Host key confirmation

A changed host key requires explicit confirmation.

Visible failure
Sessions

Preserve user work

Remote SSH, tmux, and user processes are never ended without authorization.

Keep context

Cloud data classification

Unknown fields are rejected and sensitive material does not enter the cloud in plaintext.

Sync

Non-sensitive allowlist

Only explicitly allowed preferences and model metadata can sync.

Default deny
Vault

Client-side encryption

The server stores ciphertext envelopes and key-wrapper metadata only.

Zero knowledge
Logs

Redacted records

Passwords, tokens, cookies, ciphertext bodies, and SSH details stay out of logs.

Minimum record