Security & trust · 6 min

Security and control boundaries

See exactly what monitoring, managed control, and optional remote sessions can do.

Reviewed 5 September 2026

Monitoring cannot execute commands

The monitoring process sends a signed allowlisted report every five minutes. Its response accepts only receipt data, a bounded retry interval, and an exact-schema entitlement state. It has no dispatch table, shell, configuration channel, or privileged operation.

Managed control is separate

Managed control uses another key and outbound polling process. It accepts only a closed, versioned registry of typed resources and operations. Signed timestamps, one-use nonces, leases, plan digests, resource generations, and idempotency keys resist replay and duplicate execution.

Current technical-beta boundaries

Provider API adapters are not active, and lsbs.cloud does not accept or store Hetzner or DNS-provider tokens. Hosted password/file editing and per-share permissions require Core 8.1.225 or newer. Deterministic remediation and specialized native settings need separate allowlisted capability rounds.