Security
Corenel is built so an agent can act on your machine without you having to trust it blindly. A policy checks every tool call before it runs, the folders you approve bound what it can reach, and a recording tells you afterwards exactly what it did.
The guarantees
A security promise is only worth the mechanism behind it, so the mechanism is in the second column.
| Claim | What enforces it |
|---|---|
| The agent’s file tools reach only the folders you name | @corenel/sidecar is a server you install and start yourself, with the folders it may reach given on its command line or in its own config file. Paths outside them are refused. The browser can add a folder only beneath a directory you allowed for that on the sidecar itself. A shell command you approve is not confined this way: see below. |
| Nothing is written or executed without approval or a rule you set | Read, write and execute are each checked against your policy before the call runs. The default policy lets reads run and stops every file write and command for you; the one write it allows is the agent’s own memory notes. A stricter read-only policy refuses writes outright. The shell is off until you turn it on. |
| An unrecognised tool is treated as dangerous | Every tool from an MCP server, and every call from an external agent that does not say what it does, is handled as if it mutates, so it asks rather than silently proceeding. The failure mode is an extra prompt, never a surprise write. |
| An external agent is governed on the same terms | Claude Code, driven over ACP through the sidecar, asks the same gate before each tool call, and a call aimed outside your folders is refused before the policy is even consulted. A proxied tool call is not a bypass. |
| A run can be confined to its own machine | With microVM isolation turned on, each session is a sandbox the daemon holds open behind a kernel boundary. You can pause it, snapshot it, or destroy it, and destroying it takes its contents with it. Without it, sessions run in the sidecar’s own process, still limited to your folders, and the sidecar says which at startup. |
| You can always find out what happened | Every agent and workflow run is recorded as it happens, each tool call and each decision, in order, and replayed with a scrubber rather than reconstructed from logs. |
| Nobody watching does not mean anything goes | A crew member’s policy says what happens when a run needs approval and nobody is there: refuse, wait for someone to answer, or allow. Refuse is the default. |
| A record that shows tampering | Alongside the recordings, each run writes a local audit log, on by default: append-only, hash-chained so an edited or missing line shows up, and free of prompt and file content. |
Plain answers
The things a security page usually leaves out are the things you most need in order to judge it.
| Your files do not stay on your machine | The sidecar does, but whatever the agent reads becomes part of the prompt and is sent to the model you chose. That is the job. What we avoid is a separate copy: there is no upload step, no indexing pass, and no ingest of your repository into a store of ours. |
| Built-in provider keys are held server-side | A key you add for a built-in provider is stored encrypted on our side so the gateway can use it. If you would rather we never held one, add a custom OpenAI-compatible endpoint instead: the browser calls that directly and its key never reaches us. |
| Prompts and completions pass through our gateway | Runs on a built-in provider are routed through Corenel’s gateway rather than straight from your browser to the provider. A custom endpoint is the direct path. |
| We are not audited | Corenel has no SOC 2 report and no third-party penetration test to point at. When that changes it will be stated here with a date, not implied. |
| A policy is not a sandbox escape defence | The gate governs which tool calls run. Once you approve a command, it runs with your permissions, on your machine, or inside the sandbox when the session has one. Approval is a real decision, not a formality. |
Pair a sidecar against one folder, choose the read-only policy, and see what the agent does before you grant it anything.
Nothing is granted by signing up. Every write still waits for you.