Skip to content
Trust & Security
DIJ—LABS/HOME

You hold the key.

Anyone who gives an AI agent access to their server deserves clear answers: what does it see? Where are the logs kept? And how do you cut off access?

Principles

Six principles we never compromise on.

01 · Read-only

Read-only by default

Every connection starts with read access. Nothing changes until you explicitly grant permission.

02 · Least privilege

The least privilege possible

A key or agent scoped to the task. We don't ask for the root password.

03 · Approval

Approval before execution

Every write action waits for your approval, except what you allowed in advance within a defined scope.

04 · Audit trail

Full log

Who did what and when — for every read, recommendation and action, and exportable.

05 · Revoke

Cut off access in one step

Stop the agents, delete the key, or revoke the tokens — and access ends immediately.

06 · Minimal data

The least data possible

Only what's needed for analysis, with secrets masked before anything reaches the model.

Access levels

Three levels. You choose.

01

Monitoring

Reading metrics and settings only. No changes to anything.

02

Recommendation

The agents propose the action with the reason and impact, and you decide.

03

Authorized execution

Pre-defined actions run automatically, with approvals and a clear log.

Revoke access

Cutting off access in three steps.

  1. Stop the agents from the control panel
  2. Delete the SSH key or stop the DIJ agent
  3. Revoke API tokens and cloud credentials
(FAQ) Security

The questions every careful customer asks.

Only the metrics, configuration summaries and log excerpts needed for analysis. Secrets, environment variables and passwords are masked before sending, and the contents of your databases or your customers' files never reach it.

Operation logs — what the agents read, suggested and executed — are kept in your account and you can export them. We share hosting details when you get in touch.

Three steps: stop the agents from the control panel, then delete the SSH key or stop the DIJ agent, then revoke API tokens and cloud credentials. Access ends at the first step you take.

Only within what you allow in advance. The default is monitoring and recommendations. Any other write action waits for your approval.

Engineers assigned to your account only, and every access is logged. Login credentials are not shared outside this team.

We've worked with payment companies for years. Within the Enterprise tier we discuss your compliance requirements, and add an SLA, human on-call and security reviews.

For financial firms and institutions: request a detailed security review session with our team before granting any access.

Request a security review Start with a free read-only audit