Noxgild
Security

Environment Secrets

How Noxgild keeps secret-bearing environment data out of ordinary command execution by default.

Noxgild does not treat the local process environment as an unrestricted bag of credentials.

Sanitized execution

Local execution uses a sanitized environment that excludes common secret-bearing variables by default.

A capability receives the inputs defined by its contract rather than inheriting every credential available to the host process.

Account and device credentials

Account authorization, device identity, and AI-client authorization are separate security concerns. Sharing one Noxgild backend does not make those credentials interchangeable.

One-time secrets

When the product creates a credential that is intentionally shown once, copy it at creation time and store it in the system that needs it. Later account views should expose only safe metadata.

See Data handling.

On this page