← Back to Home

Security Model

EnvoyMesh must protect the owner before it helps the network.

The most important rule is that an Envoy is not allowed to browse the owner's computer. It can only access explicitly approved data and capabilities.

Threats

Prompt Injection

A remote peer may send a malicious message that tries to convince the agent to reveal private information, ignore policy, or call unauthorized tools.

Mitigation:

Filesystem Leakage

A bug or compromised agent may try to read private files outside the shared vault.

Mitigation:

Identity Spoofing

An attacker may pretend to be a trusted friend.

Mitigation:

Sybil Attacks

An attacker may create many fake peers to appear trustworthy or overwhelm the node.

Mitigation:

Data Over-Sharing

The Envoy may share a raw document when a summary would have been enough.

Mitigation:

Security Boundaries

Diplomat

The Diplomat is the network-facing component. It handles libp2p connections, message parsing, peer identity, and rate limiting.

It should not have direct access to the private filesystem or model tools.

Bond Engine

The Bond Engine makes authorization decisions. It converts a peer identity and request intent into an allow, deny, challenge, or approval-required decision.

It should be deterministic and testable.

Brain

The Brain performs local reasoning, summarization, and retrieval-augmented answering.

It should receive only approved context from the vault. It should not be able to make arbitrary outbound network calls.

Envoy Harness

Envoy Harness runs coding agents on your home node under the same Bond Engine and approval queue as EnvoyAI. Tool calls that exceed policy, touch sensitive paths, or run shell commands enqueue owner approvals on the home node before execution — Social desktop, Terminal, and paired EnvoyGo surface the same pending items. Harness does not bypass vault path safety or grant libp2p keys to external coding runtimes.

Vault

The Vault contains owner-approved shared data.

Only data inside the vault can be indexed or shared. Access to the vault should still be mediated by document-level policy.

Minimal Permission Model

Each request should be evaluated with:

Example operations:

Example sensitivity levels:

Recommended First Version Rules

For the first prototype, use conservative rules:

Audit Log

Every meaningful exchange should create an audit event:

The audit log helps the owner understand what the Envoy did while they were offline.