API keys
Storage location, encryption, scope, use, and deletion.
DoPilot explains AI agent security and governance across model data paths, API keys, project files, plugin permissions, diagnostics, and human approval. We publish only confirmed behavior: what stays on the device, what goes to a model or third party, and which risky actions require a person’s approval.
Storage location, encryption, scope, use, and deletion.
What stays on device and what goes to models or other services.
Supported providers, authentication, request paths, and third-party terms.
Official versus community components, permissions, and risky-action approval.
Fields, purpose, defaults, retention, and opt-out behavior.
Signing, releases, vulnerability reports, fixes, and incident notices.
Connections receive only the access needed for the current task, with sensitive capabilities explicitly authorized.
Publication, payment, refund, deletion, and external commitments enter approval before execution.
The full product data policy, model matrix, and deployment matrix still await product-fact confirmation. This page does not use vision in place of verified implementation.
DoPilot addresses model data paths, API keys, project files, plugin permissions, diagnostics, and human approval separately. Unconfirmed storage or deployment behavior is not presented as shipped capability.
The final scope must be confirmed with each release. Product disclosures will cover project data, Sessions, files, prompts, model requests, logs, diagnostics, recipients, and retention periods.
Connections and plugins should follow least privilege and receive only the access required for the current task. Sensitive capabilities and risky actions require explicit authorization and human approval.
The final fields, purposes, defaults, retention, and opt-out behavior remain subject to product-fact confirmation. DoPilot will not claim a policy before those details are verified.
Publishing, payments, refunds, deletion, repricing, bulk messages, external commitments, and other risky or irreversible actions should receive approval before execution.
Clarify product facts, boundaries, and human control before the next step.