Know the boundary.
Autonomous is designed to make remote computer access explicit: the machine connects outward, the backend owns identity and routing, and the local agent decides what the operating system will execute.
Current architecture · September 2026No inbound computer port
The paired agent initiates its connection to the Autonomous service. You do not need to expose an inbound port on your computer to the public internet for normal operation.
Account and device isolation
The backend associates every paired device with an account and validates ownership before dispatch. When more than one computer is online, a device must be selected explicitly unless the choice is unambiguous.
Local filesystem boundaries
Set AUTONOMOUS_ALLOWED_DIRS to constrain filesystem tools to selected directories. Path validation resolves real paths to reduce symlink escapes. An empty allowed-directories configuration is unrestricted, so configure it before using Autonomous with sensitive machines.
Command protections
The local agent checks commands against its blocked-command policy before execution, including compound command strings. Tools that can write are flagged as potentially destructive, so an AI that reads those flags can ask before acting. A denylist is a guard, not a complete sandbox.
Credentials
| Passwords | Salted scrypt hash. |
|---|---|
| Account API keys | SHA-256 hash at rest; plaintext is only returned when a new key is issued. |
| Device credentials | Cryptographic hash at rest and scoped to device operations. |
| OAuth access | Access tokens expire after 1 hour; refresh tokens expire after 30 days and rotate. |
| Web sessions | Hashed token with a 7-day lifetime. |
Payments
Paid plans use a checkout page hosted by Stripe, so card data never reaches Autonomous. Plan changes are applied from Stripe webhooks whose signature is verified, and the plan itself is resolved from the Stripe Price of the subscription rather than from anything the browser can edit.
Data path
Tool arguments and results travel through the Autonomous backend because it relays work between the connected AI client and the paired computer. Transport is protected with TLS, but this is not end-to-end encryption where the relay is unable to see content. Tool-call records are retained for 7 days by default. See Privacy for details.
What you should do
- Pair only computers you own or are authorized to operate.
- Use a dedicated OS account or least-privilege environment for higher-risk workflows.
- Set allowed directories instead of leaving filesystem access unrestricted.
- Keep important data backed up before granting write access.
- Revoke connected clients and unpair lost, sold or compromised computers immediately.
Report a security issue
Start from the Support page or email autonomousmcp@gmail.com and identify the report as a security issue. Do not include passwords, API keys, device tokens or other live secrets in the initial report.