Skip to content
Security

What Astron can reach, and what it cannot.

An agent with tools is only trustworthy if its boundaries are explicit. These are the controls that exist in the product today, stated without exaggeration.

Controls in place

01

Server-side authorisation

Every request resolves the session on the server and verifies workspace membership before a query runs. Interface state is never treated as a permission.

02

Workspace isolation

Conversations, runs, files, artifacts, memory, connectors, and tasks are filtered by workspace on every read and write.

03

Credential handling

The model provider key and any connector tokens stay server-side. They are never exposed to browser JavaScript, public configuration, HTML, source maps, or analytics, and secrets are redacted from logs.

04

Approval before external actions

Sending, publishing, deleting, and writing to a connected tool require an explicit human approval that is persisted with its payload, decision, and timestamp.

05

SSRF protection

Page fetching rejects non-public hosts, loopback and link-local ranges, private networks, and non-http schemes. Search and page reading are separate tools.

06

Prompt-injection boundaries

Tool output is treated as untrusted data. Astron cannot escalate its own permissions or invoke a tool outside the registry, and high-risk actions still need you.

07

Audit trail

Tool executions, decisions, approvals, and cancellations are written to an append-only log you can read in the product.

08

Input validation

Request bodies are schema-validated, uploads are extension and size checked, and archive extraction prevents path traversal.

09

No arbitrary execution

Astron does not execute imported code on the application server and has no shell access or unrestricted filesystem access.

We do not claim morethan we have built.

This deployment has no OAuth credentials configured, so connectors show a setup state rather than a connection. Background scheduling is not wired up, so automations are stored but never fire on their own. Astron says so in the interface rather than implying otherwise.

Hand Astron the first task.

Create a workspace, name your coworker, and give it something you have been putting off.

Get Astron