Security
How Xroga scopes repository and provider access, protects secrets, validates operations, and reports safe evidence without exposing credentials.
Updated 2026-07-30 · Relevant product surface
Least authority
Xroga uses the repository, provider, workspace, and environment permissions the user grants. Browser code receives only public configuration. Service credentials remain server-side and logs redact secret-like values.
Repository content is untrusted
Files and external research can inform a task but cannot override platform security rules. Destructive actions must match explicit user intent and validated targets.