Security

Built around redacted control-plane records.

Runmote combines bounded metadata, explicit ownership checks, encrypted private task content, strict generic envelopes, and server-side duplicate suppression.

Hash-only credentials

Device credentials and reservation correlation data are stored as hashes or safe summaries. Raw device credentials are returned only once where existing APIs intentionally do so.

Bounded opaque tasks

Strict agent-task envelopes reject malformed or unknown fields while preserving prompt and report text without coding-semantic interpretation.

Admin visibility boundaries

Normal users see safe device lifecycle fields. Admin APIs expose sensitive client metadata only to users with the explicit permission.

Owner-controlled execution

The owner-selected workspace and Codex sandbox remain local. Runmote creates no extra file-plan or execution approval ceremony.

Browser screenshots and tests must stay redacted: no raw pairing codes after creation, no credential digests, no auth header values, no task payload dumps, and no generated browser artifacts in git. See Privacy and agent task data for the current boundary.