WHOSEPORT
Security

The model never gets a shell

WhosePort is designed so that a wrong diagnosis is an inconvenience, not an incident. These are the rules the system enforces, not guidelines the model follows.

What the system never does

What it always does

The execution boundary

flow
Cloud AI → Typed action → Policy engine → Approval → Local agent → Result → Verify

The cloud can reason, compare snapshots and produce plans. It cannot run commands or read files. Only the local agent has OS access. It reads project .env files for variable names and host and port targets only, and it accepts typed actions from a fixed list, never natural-language instructions.

Actions

ClassActionsDefault
Low riskhttp_retry, refresh_snapshotAllowed
Mutatingstop_process, restart_process, restart_container, update_runtime_configRequires approval
Not an actionShell commands, file deletion, volume removal, Docker pruneCannot be proposed at all

Data handling

Reporting a vulnerability
Email security@whoseport.com with the details and steps to reproduce. Please give us a chance to fix the issue before disclosing it publicly.