Security
Security and control
Understand the controls in the current alpha, choose the right action posture, and verify the boundaries for your own workflow.
Start with the actual defaults
Proto can take actions, including editing files and interacting with connected services. Its settings are part of the operating decision. New installs start with Uninterrupted mode on: Proto chooses recommended options and runs confirmable actions without questions or review prompts. Missing credentials and hard blocks are reported instead of waiting for an approval that cannot be supplied.
Turn Uninterrupted mode off in Settings > Permissions when work should pause for input or review. With it off and outside Plan mode, consequential browser actions, consequential native desktop actions, and dangerous shell commands request approval. Plan mode should not be treated as a universal read-only sandbox.
For an initial evaluation, choose the mode deliberately and test an action that should pause. A written instruction can define the scope of a task, but it does not replace checking the application settings and the permissions of the connected account.
ERP•AI has separate protections
Deletion and sensitive ERP•AI actions are disabled by default in Settings > Security. Sensitive actions include changes to roles, user access, and invitations. These controls are separate from Uninterrupted mode and from the user’s permissions in ERP•AI.
| Control | What it governs |
|---|---|
| Permission mode | Whether confirmable actions proceed or request review |
| ERP•AI Security settings | Whether deletion or sensitive access operations are available to the agent |
| ERP•AI account permissions | Which app resources and operations the signed-in user can access |
| Operating-system permissions | Access required for device-level capabilities |
Wiping an ERP•AI app requires a person to type the app’s name. Certain root-level destructive shell patterns are hard-blocked. These protections address specific operations; they are not a guarantee that every possible harmful action can be recognized in advance.
Know where task information goes
Workspace files, memory, and local session records are stored on the machine. Selected messages and context are sent to the model service used for the task. ERP•AI task conversations are also saved in app history, and plugin actions send their requested data to the configured endpoint. Browser uploads and form submissions have the destination site’s data handling.
Review these paths before using sensitive material. A local workspace is not a blanket data-residency commitment, and choosing a model provider does not establish the retention or contractual terms of every connected service. Assess those terms for the actual configuration you intend to use.
Treat external content and extensions as inputs
Documents, web pages, and tool results may contain misleading information or instructions. Proto’s document readers do not execute embedded macros or scripts during extraction, but an analysis still needs review against its sources.
Skills can contain scripts, and local MCP servers run as processes. Inspect their source and dependencies and use accounts with only the access needed for the task. A connector’s permissions and the trustworthiness of its operator remain part of the evaluation.
Evaluate the alpha against your requirements
Native desktop control is experimental and off by default. Release availability, provider behavior, and action controls should be checked in the installed version. This overview describes current product behavior; it does not assert an independent security certification or a compliance outcome.
Before expanding use, verify a representative task with your intended account, action mode, source material, and destination. Confirm the pauses, inspect the resulting changes, and decide who owns review and recovery. Where an organizational requirement is not demonstrated by the product or an agreed service commitment, treat it as an open requirement.