Security & privacy
Security & privacy
What never leaves a machine
The session transcript — everything you typed and everything the agent did — stays on the laptop it happened on. Reviews read it locally. What travels to the hub is the finished skill text, after the safety checks.
Secrets
Anything credential-shaped blocks publication before a model ever sees it, and the hub re-runs that check server-side on every publish path — a client is not a security boundary. Error messages name the kind of secret found, never the secret itself.
Who sees what
- Skills can be scoped: company-wide, or to named people. Scoped skills are
- The website: the public sees this documentation and the product pages.
invisible to everyone else — in the library, in search, in usage counts, and on the web — and asking for one by name returns not-found, not forbidden.
Optivaize accounts can browse the shared hub read-only. Creating an account takes a one-time code: mailed when the hub has a mailer, and otherwise relayed personally by the owner — either way, an address alone opens nothing. Owner controls require the owner's credential; hiding a button is presentation, and every mutating route enforces the rule server-side.
Provenance and history
Every version records who published it, which agent authored the text, and under which curation policy. Nothing is ever deleted: archives are restorable, merges keep their sources, and the audit log records every administrative action.