Security and privacy
Local control plane
Section titled “Local control plane”Dovik has no network control port. Native clients connect through a current-user Windows Named Pipe or private Unix Domain Socket. The daemon is the only process that writes registry and runtime state.
Private state
Section titled “Private state”The registry and identity metadata live in private per-user storage outside project repositories. Writes use a temporary file, flush, and atomic replacement. Credentials are not stored in identity metadata.
Environment override values are accepted only when defining a process and are omitted from list and status responses. Process commands, arguments, working directories, and captured output remain visible to authorized clients and may contain sensitive text produced by the project.
GitHub credentials
Section titled “GitHub credentials”The ordinary proxy obtains the configured project credential through a bounded helper operation and gives it only to the original GitHub CLI child environment. It preserves the full GitHub CLI command surface except GitHub CLI authentication mutation and direct token export. Native and container agent-isolation sessions additionally validate repository, command, flags, and policy through the governed executor. Tokens do not enter process arguments, state files, or diagnostics. Dovik never changes the globally active GitHub account. User-installed aliases and extensions run with the operator’s own privileges and remain outside the proxy-level security boundary.
Boundaries
Section titled “Boundaries”Proxy-level enforcement is bypassable by another process running with the operator’s privileges. Use a prepared native or container isolation boundary when that risk is unacceptable. Dovik does not install accounts, engines, credentials, or PATH shims automatically.