Trust boundaries

Security

What we try to protect, where the walls are, and how to report a hole. The privacy page is the one that says what data leaves the browser. This page is about who can reach what after that.

Threat model

Aperture is an editor that runs agent-written code and talks to model providers with your keys. The main risks we design against:

Honest limits

Sandbox limits (summary)

SurfaceBoundary
In-tab testsWorker in sandboxed frame, opaque origin, CSP blocks network. ~10s budget.
Preview / render checkScript-sandboxed frame with an opaque origin.
Server verify runDeclared package.json scripts only (no dev/start/watch). Closed env. Registry allowlist. Time cap.

Vulnerability disclosure

Please do not report security problems in public issues.

Report them privately through GitHub: open the repository's Security → Report a vulnerability form. Include what an attacker could do, the steps to reproduce it, and the version or commit you tested. You'll get an answer within a week.

The same policy lives in SECURITY.md. Areas where a report is especially welcome: the in-browser test runner (src/lib/runner/), preview and render-check frames, the agent's run allowance and sandbox env (src/lib/sandbox/policy.ts), and sign-in / session handling.

Questions about data handling go to the privacy page. How often checks stop a bad edit is on the checks benchmark.