DocumentationSecurity
Docs/Secure and govern

Security

Understand where AI code runs, how network access is limited, and where credentials stay.

Runtime boundary

Hermes is OpenNeko's sole agent runtime. Agent jobs and plugins always run inside separate OpenShell policy sandboxes; there is no unsandboxed production path.

  • Outbound network access is default-deny.
  • Each permitted destination is tied to the approved executable or plugin manifest.
  • The model API key never enters the agent sandbox. The gateway injects it on the wire.
  • The control plane keeps approvals, secrets, audit records, and durable writes outside the sandbox.

Secrets

Plugin and provider secrets are encrypted or stored in the deployment secrets file with restricted permissions. They are not written into tracked plugin configuration or logged action payloads.

Operator responsibilities

  • Put remote deployments behind a TLS reverse proxy.
  • Patch the host, Docker runtime, OpenNeko, and installed plugins.
  • Limit administrator access and review connected accounts.
  • Export recovery keys and audit evidence to systems with appropriate access and retention controls.
  • Review allowlists whenever a plugin or solution pack changes.