Skip to content
Agentouch

Security and trust model

Do not trust the agent. Trust the infrastructure.

An AI coding agent is an untrusted process that reads text out of your repository, and text in a repository can contain instructions. Designing around that is not a feature we added; it is the shape of the system. Below is what that means concretely, including where the limits are.

01 Your code stays where it is

  • A single Go binary runs on your own host. The repository is cloned there, worked on there, and pushed from there to your own git provider.
  • The control plane sends typed jobs with typed payloads — never an arbitrary shell command — and never receives your source code.
  • Status that the control plane needs is read from your git provider's API, not forwarded by the runner.
  • Works with a model running inside your own network through any OpenAI-compatible endpoint.

02 What the agent container cannot do

  • It holds no git token and no Docker socket. It cannot push, and it cannot reach the host's container runtime.
  • The git directory is never mounted into it, so it cannot modify git configuration or hooks. Every git command runs with hooks disabled.
  • Egress is allow-listed per adapter: the AI provider's endpoint and your package registry. Private ranges, link-local metadata addresses, the host, and Agentouch's own network are all blocked.
  • Read-only runs — review and planning — mount the working tree read-only.

03 The runner is not trusted either

  • The server re-derives the head commit from the provider's API rather than believing what the runner reported.
  • The diff and the CI status are read from the provider, not from the runner.
  • Verification runs on the runner and is treated as advisory. It is never, on its own, sufficient grounds for an automatic merge.
  • A runner that stops sending heartbeats has its containers reaped after two minutes.

04 Nothing merges by itself

  • Every merge condition is off by default, and Agentouch never merges when they are off.
  • Conditions you can switch on: CI green on the head commit, an approving review verdict, a change-size limit, no sensitive paths touched, and no unresolved change requests.
  • The Agentouch configuration file in your repository is always treated as a sensitive path and always requires a human.
  • Each decision is written down with its result and its reasons, which is what an audit asks for.

05 Text from outside is data, never instructions

  • Issue bodies, review comments and repository content are wrapped as data with an explicit instruction not to follow anything inside them.
  • An issue opened by someone who is not a member cannot start work on its own; a member has to act first.
  • Intake never queues an implementation run. The worst case from hostile text is a wasted read-only run with no credentials and restricted egress.

06 What is recorded

  • Runs, their steps, and their logs separated by stream — system, standard output, standard error, agent events.
  • Terminal sessions: who opened one, into which container, from which address, and why it ended.
  • Merge decisions with reasons, and webhook deliveries with their payloads.
  • Which agent, which agent version and which model produced each run, so results can be compared.

Where the limits are

Points we would rather you hear from us than discover during a procurement review.

  • Single sign-on, SAML and a formal compliance certification are not available yet. If your purchase depends on them, tell us and we will be straight with you about timing.

  • Shared AI quota across a team is designed so that the borrowing side's code runs with access to the lending side's agent credential. That is stated in the consent both people must accept. Only enable it inside a team that genuinely trusts each other.

  • A sandbox needs a configuration file in your repository declaring its image, setup and processes. Without one, a task can still produce a change — but not a live preview.

Want the long version?

There is a written specification behind each of these claims, and we will walk a security reviewer through it directly.