SECURITY · TRUST
Release details pending

You should always know where your data goes.

DoPilot explains AI agent security and governance across model data paths, API keys, project files, plugin permissions, diagnostics, and human approval. We publish only confirmed behavior: what stays on the device, what goes to a model or third party, and which risky actions require a person’s approval.

Data pathsLeast privilegeHuman approvalStatus disclosure
DISCLOSURE

These questions must be answered before release.

01

API keys

Storage location, encryption, scope, use, and deletion.

02

Projects and Sessions

What stays on device and what goes to models or other services.

03

Models and services

Supported providers, authentication, request paths, and third-party terms.

04

Plugins and permissions

Official versus community components, permissions, and risky-action approval.

05

Telemetry and diagnostics

Fields, purpose, defaults, retention, and opt-out behavior.

06

Updates and security contact

Signing, releases, vulnerability reports, fixes, and incident notices.

DESIGN PRINCIPLES

Control AI agents with least privilege and human approval.

01

Least privilege by default

Connections receive only the access needed for the current task, with sensitive capabilities explicitly authorized.

02

Risky actions go to people

Publication, payment, refund, deletion, and external commitments enter approval before execution.

!

Current status

The full product data policy, model matrix, and deployment matrix still await product-fact confirmation. This page does not use vision in place of verified implementation.

FREQUENTLY ASKED QUESTIONS

Common questions about this product.

How does DoPilot approach AI agent security?

DoPilot addresses model data paths, API keys, project files, plugin permissions, diagnostics, and human approval separately. Unconfirmed storage or deployment behavior is not presented as shipped capability.

What stays on the device and what is sent to a model?

The final scope must be confirmed with each release. Product disclosures will cover project data, Sessions, files, prompts, model requests, logs, diagnostics, recipients, and retention periods.

How are plugin and tool permissions controlled?

Connections and plugins should follow least privilege and receive only the access required for the current task. Sensitive capabilities and risky actions require explicit authorization and human approval.

Does DoPilot collect telemetry or diagnostics?

The final fields, purposes, defaults, retention, and opt-out behavior remain subject to product-fact confirmation. DoPilot will not claim a policy before those details are verified.

Which AI agent actions require human approval?

Publishing, payments, refunds, deletion, repricing, bulk messages, external commitments, and other risky or irreversible actions should receive approval before execution.

NEXT STEP

Start with one real task.

Clarify product facts, boundaries, and human control before the next step.

Contact DoPilot