Resources
Security
Controls for verification, accounts and connected coding sessions.
Verification worker separation
The verification API authenticates a request and queues a job. Gate execution runs in a separate worker process with a restricted environment, rather than inheriting the API server’s full environment. The queue removes the temporary job directory through its completion and failure cleanup path.
This is a process and environment boundary. Its protection depends on the deployed worker, host permissions and gate implementation; it is not a claim of a formally verified sandbox.
Authentication and ownership
The server implements signed session tokens, scoped API credentials, CSRF protections for cookie-authenticated requests and OAuth state checks. Relay session access is checked against the caller’s identity. Protect your credentials and review account access when connecting shared workspaces.
Request and resource limits
The API enforces request-size and rate limits, and the relay bounds retained session events and subscriber buffers. These controls reduce oversized-request and resource-exhaustion risks. A rate-limit response means the request must wait or be reduced; it is not a successful verification result.
Check records and sensitive data
Audit events include session and trace identifiers. The event logger redacts fields whose keys identify credentials and limits long strings. This does not guarantee removal of secrets embedded in ordinary conversation text or source code.
Verification job cleanup does not delete every type of account, audit or relay data. Read Privacy for the separate data flows.
Your local workspace
Asondy runs with the permissions of the local environment in which it is installed. Hook enforcement depends on the coding tool. Keep operating-system permissions, repository protections and review rules appropriate for your project. Do not rely on an agent’s statement alone when a result needs an independently repeated check.
Assurance and scope
The controls described here reflect the project’s implementation. This page does not claim SOC 2 certification, universal guard coverage or a guarantee that software is free of vulnerabilities. Deployment-specific controls and contractual requirements need to be assessed for the service you use.