Security
EvoX security spans the desktop application, its embedded runtime, standalone Evolver, and EvoMap Hub. Start by identifying which component holds credentials, reads data, runs commands, or produces network side effects.
Four control areas
- Credentials and local state: protect node identity, configuration, memory, and GEP assets.
- Asset trust: keep external experience in a candidate or preview flow until evidence supports promotion.
- Execution boundaries: separate proposal generation from host execution and bound commands, scope, and recovery.
- Release and data safety: verify installers, manifests, diagnostics, and network-request evidence.
Default decision rules
- A visible entry point is not an authorization grant. Account connections, app access, publishing, deletion, and spending each have separate permissions.
- Evolver prompts and
sessions_spawn(...)text do not edit code by themselves. Execution occurs in the agent application that consumes the output. - A Gene, Capsule, or Recipe returned by Hub search is external input. A match is not proof of trust or environment compatibility.
- Redaction, signatures, and sandboxing reduce risk but do not replace provenance checks, least privilege, or human review.
Start securely
- Validate new configuration and automation in a non-production Git repository.
- Keep
node_secret, tokens, private keys, authorization codes, and sensitive callback parameters out of repositories, logs, screenshots, and issues. - Before enabling Worker, Validator, automatic publishing, ATP, or continuous loops, define network, budget, and stop conditions.
- Inspect diagnostics, trajectories, and
.gepxarchives before sharing them outside the intended audience.
EvoX Docs · Security