Powerful automation deserves explicit security boundaries.
MCPENROUZ separates account identity, AI authorization and device credentials. The local policy on each machine remains authoritative for every privileged action.
1. Device-local permissions
Readable paths, writable paths, terminal access, deletion, OS process listing and process termination are separate settings. The cloud service cannot silently expand them.
2. Credential separation
AI clients authenticate through OAuth. Device credentials remain with the local agent and are never exposed through the account interface.
3. Outbound network model
The agent connects to MCPENROUZ over outbound HTTPS. Normal use does not require a public inbound device port.
4. Data minimization
Operation inputs and results are transmitted only to perform the requested action and are not designed as a permanent content archive. Operational audit focuses on metadata and outcomes.
5. Sensitive environments
Use a restricted OS account, container, VM or dedicated machine. Allow only the project paths required for the workflow.
Report a vulnerability
Email security@penrouz.com. Do not include live passwords, tokens or device credentials.