Least privilege

AI access within approved boundaries

RepoTunnel's privileged local boundary is implemented in Rust and separates workspace access, command execution, Git publishing, browser actions, desktop control, phone access and remote transport into distinct policy surfaces.

Approved workspace roots

AI-facing file tools use workspace IDs plus relative paths. Absolute paths, parent traversal and symlink escapes are rejected.

Protected secrets

Common environment files, private keys, credential files and secret-bearing paths are denied even inside an approved project.

Fail-closed commands

Linux uses Bubblewrap, Windows uses AppContainer + Job Object, and macOS uses the current Seatbelt compatibility backend. No silent unrestricted fallback.

Review is local

Remote MCP cannot approve or reject its own queued AI Review file, command or Git actions.

Push stays explicit

AI Auto is not standing permission to publish. Git push requires a current explicit human instruction and a final secret preflight.

Raw MCP stays loopback-only

Public access is routed through RepoTunnel's authenticated connection boundary rather than exposing the raw local gateway.

Browser mutation receipts

Uncertain clicks/types are reported as ambiguous instead of blindly replayed after helper transport loss.

Desktop self-control blocked

Desktop permission is explicit and RepoTunnel itself cannot be targeted by its own AI desktop control path.

Phone escalation blocked

MCP cannot pair/select a different phone, raise Phone permissions or unpause AI access. Payment-sensitive foreground apps block AI control.

Read the technical security documentation

The website summarizes the model. The repository remains the canonical source for implementation details, security policy and release acceptance tests.

Start typing to search.