Security & trust · 6 min
Security and control boundaries
See exactly what monitoring, managed control, and optional remote sessions can do.
Monitoring cannot execute commands
The monitoring process sends a signed allowlisted report every five minutes. Its response accepts only receipt data, a bounded retry interval, and an exact-schema entitlement state. It has no dispatch table, shell, configuration channel, or privileged operation.
Managed control is separate
Managed control uses another key and outbound polling process. It accepts only a closed, versioned registry of typed resources and operations. Signed timestamps, one-use nonces, leases, plan digests, resource generations, and idempotency keys resist replay and duplicate execution.
Current technical-beta boundaries
Provider API adapters are not active, and lsbs.cloud does not accept or store Hetzner or DNS-provider tokens. Hosted password/file editing and per-share permissions require Core 8.1.225 or newer. Deterministic remediation and specialized native settings need separate allowlisted capability rounds.