SECURITY ARCHITECTURE

Cloud for identity. Machines for the work.

Security in CodeTether is a set of authority boundaries. Each layer owns one thing, and none of them quietly becomes the other.

FIVE SEPARATE ROLES

Trust is not one green dot.

Account authentication, ProductDevice authorization, Host ownership, Machine Controller trust, and Relay enrollment answer different questions.

01

Account

Human identity and ownership claims.

Your login does not grant execution access by itself.
02

ProductDevice

A device key authorized to supervise.

Revocation is explicit and separate from account auth.
03

Host

The durable workspace authority.

Projects, Conversations, Turns, and Provider selection stay local.
04

Machine trust

A pinned Controller <-> Node relationship.

Pairing is explicit and transport is authenticated.
05

Relay

Opaque rendezvous and transport.

Relay never becomes workspace or Provider authority.
PRIVACY BOUNDARY

What CodeTether Cloud is not meant to store.

Source codeProvider credentialsPrompts and transcriptsTerminal outputRaw diffsFilesystem paths

Build where your code lives. Supervise from anywhere.

Explore downloads