Security boundary

A deliberately small authority surface.

The local product constrains what can be inspected, executed, persisted, and applied. AI output does not gain direct shell, patch, answer, or repository authority, and every unsupported condition fails closed.

Local by default

Runrail Desktop binds only to 127.0.0.1. Repository content and generated review artifacts stay on the operator's machine.

Allowlisted execution

Runrail accepts supported workflows and verifier commands, not arbitrary shell instructions.

Human-controlled apply

The product exports a patch for review and does not apply it automatically.

Auditable output

Patch, audit, review, rollback, and policy evidence remain attached to the review.

Local revision evidence

The free browser workspace compares related audit files without opening either repository or sending files to Veyact. Licensed CLI comparison is available in Pro and above.

Model-independent core

Offline deterministic recommendations require no model. Optional DeepSeek advice receives no source or diff and may return only fixed candidate IDs or ABSTAIN, with authority none.

Path traversalRejected
Arbitrary shellRejected
Automatic source mutationDisabled
External model providerNot required; separate BYOK metadata-only advisory is opt-in

Security detail

Review the full boundary and current limitations.

Open safety docs