Security
Verified local security behavior for Allfixx Agent. This is not a certification or a guarantee.
This is a local product document. Clauses marked Review needed require final legal or company details. They are not complete legal advice or a filed policy.
Security Overview
Allfixx Agent on this machine is a local workspace. You attach a folder on disk. The product is built so explorer, editor, and terminal stay attached to that tree.
This page does not claim that the product is fully secure, risk-free, certified, or encrypted to a named standard. No audit report is published here.
Workspace Security
You choose the folder. Path checks are part of the product so workspace operations are meant to stay inside that root.
Those checks are not a substitute for opening the correct directory or for operating system permissions on this computer.
Agent Permissions
Ask mode is for reading and explanation. It is not the path for applying file writes.
Agent mode can propose patches and terminal commands. Writes and commands that require approval wait until you accept or reject them. The product is not designed as an unsupervised tool loop.
If the file changes after an approval is issued, the product can invalidate that approval and ask again.
API Key Handling
Provider credentials are not shown in the public browser UI. Do not paste keys into chat, documentation, or issues.
This page does not list environment variable names, key files, or provider identifiers.
Account Security
This local instance does not create a hosted Allfixx account. There is no cloud password reset on this site.
Review needed: hosted authentication, SSO, and session controls would be described only if those features exist.
Reporting Security Issues
Review needed: a public security contact and disclosure process have not been published.
For this local install, treat suspected issues as operational problems on this machine. Do not include secrets in public reports.