Security

How Xroga scopes repository and provider access, protects secrets, validates operations, and reports safe evidence without exposing credentials.

Updated 2026-07-30 · Relevant product surface

Least authority

Xroga uses the repository, provider, workspace, and environment permissions the user grants. Browser code receives only public configuration. Service credentials remain server-side and logs redact secret-like values.

Repository content is untrusted

Files and external research can inform a task but cannot override platform security rules. Destructive actions must match explicit user intent and validated targets.