Security

Check The Controls That Affect Agent Actions

Open Approvals to review pending actions. Open Settings → Permissions to change the default approval policy or Safe Mode.

Approval detail with the requested action and review controls

Overview

Neotask is designed with a security-first architecture. The Gateway binds to localhost by default, all sensitive data is encrypted at rest, and agent execution can be sandboxed in isolated containers.

Network Security

Loopback by Default

The Gateway only listens on 127.0.0.1 (localhost) unless you explicitly change the binding mode. No external network exposure by default.

Authentication

All WebSocket connections require authentication:

Remote Access Security

For remote access, the recommended approach is Tailscale VPN or SSH tunneling, never expose the Gateway directly to the internet.

Device Pairing

How Pairing Works

Every client that connects to the Gateway must be paired:

  1. Device presents its identity (fingerprint + public key)
  2. Gateway issues a pairing challenge (nonce)
  3. Device signs the nonce with its private key
  4. You approve the device through the UI
  5. Gateway issues a device token for future connections

Trust Model

Encryption

Data at Rest

Data in Transit

Sandboxing

Docker-Based Isolation

Agent command execution can be sandboxed in Docker containers:

Sandbox Scopes

Scope Description
Per-session Fresh container for each session
Per-agent Persistent container per agent
Shared Shared container across agents

Workspace Access

Sandboxed agents can access their workspace directory (mounted into the container) but cannot access the host filesystem outside their workspace.

Exec Approvals

Guardrail settings define which classes of agent actions pause for review. Check them before changing the policy for an individual request.

Agent guardrails and approval controls

Control what commands agents can execute on nodes and the Gateway host:

Modes

Mode Description
Allowlist Only pre-approved commands execute
Ask Unknown commands prompt for user approval
Full No restrictions (use with caution)

Per-Node Configuration

Each node (macOS, headless host) has its own exec approval configuration, stored locally. You can allow specific binaries (e.g., /usr/bin/docker, /usr/local/bin/terraform) while blocking everything else.

Elevated Mode

Some operations require running on the Gateway host directly (not in a sandbox). Elevated mode is:

Security Audit

The built-in security audit checks:

The audit can automatically fix many issues when given permission.

Best Practices

  1. Keep the Gateway on loopback, Use Tailscale or SSH for remote access
  2. Enable sandboxing, Run agent commands in Docker containers
  3. Use exec allowlists, Restrict what commands agents can run on nodes
  4. Set auth tokens, Always configure token auth, even for loopback
  5. Review agent permissions, Use minimal tool profiles where possible
  6. Keep Neotask updated, Updates include security patches
  7. Audit regularly, Run security audits to catch misconfigurations
  8. Restrict plugin loading, Only install trusted plugins