Security
Defense in depth.
Autonomous workers can be run with layered safeguards — from network-level SSRF guards to prompt-injection detection, secret scanning, governance gates and append-only verification receipts.
Security Layers
Layered safeguards for worker actions
Depending on runtime configuration and the operation, outbound requests, tool calls and memory writes can pass through validation and review gates. Rejections and errors are surfaced for operator inspection.
Blocks loopback, RFC1918, link-local, CGNAT, and metadata IPs. Per-hop redirect validation with a configured hop limit helps reduce DNS rebinding and open-redirect abuse.
Pattern-based checks cover phrases such as ignore_previous, disregard_above, you_are_now and system_prompt_leak. Untrusted content can be wrapped with boundary markers before it enters the LLM context.
config.toml, memory.db, bible.md, safety.md, secrets.toml, .env, and credentials are blocked from agent modification. Critical configuration is read-only at the tool level.
API keys (sk-, AKIA, ghp_, xoxb-, Bearer tokens, PEM blocks) are detected and blocked before they can reach the memory store or be exposed in tool outputs.
Pattern checks can block rm -rf /, mkfs, fork bombs, dd of=/dev, chmod -R 777 /, and other catastrophic shell commands before they reach the executor.
Repeated tool-call patterns can trigger warnings or stops according to configured thresholds, helping operators review runaway behavior before side effects accumulate.
An append-only JSONL ledger can record typed verification receipts, giving operators an audit trail to inspect alongside failures and approvals.
Bearer token or X-Api-Key header required for non-loopback binding. Authentication is mandatory when the server is exposed beyond localhost — no accidental public APIs.
A sliding-window policy can limit requests per authenticated principal and return 429 with Retry-After headers when the configured limit is exceeded.
Configured response-size and text-length limits, together with per-hop SSRF checks on redirects, help reduce memory exhaustion and internal-network exfiltration.
save_contacts, git_push, and other side-effect tools require explicit human approval before execution. The agent requests, the operator decides.
Permissive CORS only when API authentication is enabled. With auth disabled, CORS is restricted to prevent unauthorized cross-origin access to the agent API.
Verification Pipeline
Sequential email verification
A configured email-verification workflow can run through sequential stages, with typed receipts for review. Failures may short-circuit the pipeline according to its policy; results still require operator judgment.
RFC 5322 validation. Rejects malformed addresses before any network call.
DNS MX record resolution. Domains without mail exchangers are rejected.
Known disposable email providers are flagged and filtered out.
info@, admin@, support@ and similar role addresses are flagged as low-value.
Live SMTP handshake to verify the mailbox actually exists without sending mail.
Hardware-Grade Isolation
The Ironclad Credentials Vault
API keys, passwords, and database tokens are encrypted with AES-256-GCM via the Rust ring crate. Secrets are resolved in memory before TLS dispatch — LLM prompts never see plaintext credentials.

Fig 5.1 — Hardware Credentials Vault: AES-256-GCM encrypted key derivation with zero LLM prompt visibility and fail-closed audit log telemetry.
Regulatory Audits
Autonomous Legal & Compliance Verification
Multi-jurisdiction contract and policy audits: evaluating vendor Master Services Agreements against GDPR, CCPA, and statutory liability limits with paragraph-level citation traceability.

Fig 5.2 — Regulatory Document Auditor: Automated compliance evaluation across 200 vendor agreements in under 30 minutes.
Make worker actions reviewable
Choose and configure the safeguards, authentication, rate limits and approval gates that fit your deployment. Read the security architecture and verify the active policy in the documentation.