Four modes
Ask, Auto, Plan, Full. Plan mode is read-only and refuses outright: it hands you the plan and tells you to switch mode if you want it carried out. A mode is a ceiling, not a suggestion.
An agent that can read your files, run commands on your machine, write to your databases and publish to the internet is only safe if you decide what it touches. Every tool belongs to a permission category; the category — not the tool — decides what is asked of you. Three acts can never be approved in advance, in any mode.
None of them is the model's good judgement. A model that decides correctly ninety-nine times out of a hundred is not a permission system.
Ask, Auto, Plan, Full. Plan mode is read-only and refuses outright: it hands you the plan and tells you to switch mode if you want it carried out. A mode is a ceiling, not a suggestion.
Reading, writing, running a command, changing a database or bucket, writing a DNS record, sending a message, publishing to the internet, spending credits. Reading never asks. A database or DNS change is asked even in Auto mode.
Sending a message to someone, publishing on the public internet, and spending credits on something other than a model call. Asked every single time, including in Full access — « always allow » does not exist for any of the three, because none of them can be taken back.
Each run carries a credit budget. It stops when it reaches it, rather than letting you discover the cost afterwards — and a tool that spends asks first regardless of what the budget still allows.
Written from the code that implements them. Where a measure has a limit, the limit is further down the page rather than left out.
A security page that only lists strengths is a brochure. These are the limits we know about.
Write to contact@iagenify.com with « Security » at the front of the subject line. Include what you did, what you saw, and the reference if the platform gave you one. If a proof of concept touched data, say whose — including if it was your own.
A person, not a queue. If it is real you will hear what we are doing about it.
There is no payment and we are not going to pretend otherwise. Saying so up front is fairer than letting you find out after the work.
No denial of service, no third party's data, no account that is not yours. Enough to show it, and then stop.
Read, delegate to a subagent, and write its own notes. Everything else depends on the category and the mode: a file write is free in Auto, a database or DNS change is asked even there, and sending, publishing or spending is asked every time whatever the mode says.
On the device the agent ran on. Our database keeps the step — which tool, a short target, whether it worked, what it cost, how long it took — and never the content of a result. That split is deliberate: the record of what happened is useful to you, and the contents of your files are not ours to hold.
No. The address check is on by default even in development, and the one place a workflow could have been pointed at a private address has that escape switched off by default — the API is public, and a dev-time convenience there would have let any account read a response from our own network.
Replace it. Keys are stored as a hash, not as the key, so we cannot show you one back — only issue a new one and retire the old. A session derived from a key is short-lived and tied to a session family we can end.
No. Write to us anyway, with « Security » at the front of the subject. We would far rather hear it from you.
Not by a third party. The checks are ours: unit suites with no network, a script that reads each container bound back from inside the container, one that creates a throwaway account and deploys a real site before deleting everything it made, and one that exercises the sign-in path end to end. We would rather tell you whose checks these are than let the word « verified » do the work.