./SECURITY

scoped envprivate keysprovider boundary

Isolated by default

The dashboard never needs raw provider secrets on the client. Machines receive only the environment they need, and the UI exposes lifecycle controls through the provider abstraction.

capability tracetrace
01credential gate passed
02provider env scoped
03client secrets redacted
04lifecycle controls enabled

Metrics

The dashboard surfaces the moving parts.

Secret exposure

0

raw keys in browser

Machine records

scoped

per account

Controls

explicit

wake, pause, delete

Flow

How this works inside a machine.

01

Gate

Validate credentials before provisioning begins.

02

Scope

Attach only the selected provider and model environment.

03

Audit

Track lifecycle, logs, and usage from the dashboard.