Security

Security is the product.

XR was designed with a security core, not security bolted on. Capabilities, sandboxing, and audit are fundamental primitives.

Capability-based security

Each skill receives only the capabilities it explicitly requests — file paths, network domains, and environment variables.

Sandboxed execution

Skills run in hardened micro-sandboxes with syscall filtering, filesystem namespaces, and restricted network egress.

Secrets & key management

Encrypted vault with per-skill scoping, rotating credentials, and just-in-time approval for sensitive access.

Human-in-the-loop

Confirm dangerous actions before they execute. Configure policies by skill, repository, and risk level.

Signed packages

Every skill is signed by its author. The runtime verifies signatures before execution.

Audit & replay

Every run produces an immutable audit log. Replay sessions end-to-end for debugging and compliance.

SOC 2 Type IIISO 27001HIPAA-readyGDPRCCPA

Request our security dossier.

Including our SOC 2 report, penetration test summaries, and architecture whitepaper.

Request dossier