afire.ai closed alpha
Sign in Request access
security

An agent on a computer is a serious thing

Software that can see a screen and run commands deserves more scrutiny than a web app. This page describes current practice, honestly and without guarantees — it changes as afire matures.

status

Where afire is today

practices

Practices

Signed updates

Agent releases are signed, and each agent verifies the signature on-device before applying an update. An unsigned or altered release is refused. Signing keys are kept off the production environment.

Outbound-only agents

Devices connect out over TLS. The agent doesn't listen for inbound connections on the hardware it runs on.

Reduced privileges

The platform service runs as an unprivileged user, and agents only receive tools the device supports and the session allows — a headless server doesn’t expose screen control.

accountability

Accountability

data

Data

The privacy policy states what is collected and how long it is kept. The terms cover what the service is and isn't responsible for.

reports

Reporting something

Found something? Use the request-access form on the front page and lead with the word security — those go straight to a human. Reports are welcome, including during the alpha.

next
Privacy policy
What is collected, and how long it is kept
back
Product
What afire is and what it does