Security / VEYLUM

Useful, with clear boundaries.

Permission before action

Decide what Veylum may do.

ALLOW

Permit a supported operation within the configured scope. This does not override product safety rules or authorize arbitrary commands.

ASK

Pause for explicit review. Check the proposed paths and exact changes; write approvals are one-use and become stale when relevant workspace state changes.

DENY

Refuse the operation. Imported content or a model request cannot elevate this policy.

Bounded Windows tools

A workspace is a boundary.

Choose an attached project folder with the operating system picker. Supported file tools resolve workspace-relative paths and enforce containment, sensitivity restrictions, output limits, and permissions. A model cannot turn a read into an unrestricted disk scan.

An opt-in Development bot can propose create, edit, patch, rename, or delete actions. Review exact edits in the existing approval flow; delete also requires typed path confirmation. The fixed offline Node test profile uses a restricted Windows process with network and outside-workspace access denied. It is for dependency-free JavaScript tests, not general build commands.

Git actions are structured and local. There is no exposed raw shell, Git push, reset, or clean tool. Tool activity is audited; task cancellation and restart do not grant new access.

Workspace containment is not a guarantee against an administrator or another process running as your Windows user and altering files concurrently. Use trusted folders and review proposed edits.

More surfaces, the same authority

Pairing does not mean unlimited access.

Mobile HTTPS and revocation

Mobile access is off by default and binds to a selected private LAN address. A local certificate, expiring invitation, desktop approval, and revocable session establish access. Trust only your desktop’s identity. Stop the listener or revoke a device when needed.

Approval surfaces

Current paired personal-chat sessions do not grant project file, command, Git, or approval authority. Broader companion access remains in final release validation.

Backups and restore

Backups contain private data, are integrity-checked, and do not include model weights. Restored workspaces require fresh folder authorization. Keep an independent private backup before migration or restore.

Release integrity

Compare the exact package SHA-256 before running it. Preview builds are currently unsigned; signing requires external credentials. Genuine previous-version rollback remains unverified. There is no configured automatic updater.

Check package identity →