Noxgild
Security

Local Execution

Understand what Noxgild executes on the authorized computer and what cloud services coordinate.

Noxgild is not a cloud-hosted replacement for your computer. The local runtime performs the work that needs local state.

Local work

Depending on the requested capability, the authorized computer can perform:

  • file and directory operations,
  • terminal commands,
  • managed processes,
  • browser rendering and interaction,
  • screenshots,
  • accessibility-based desktop automation,
  • and other cataloged local actions.

Cloud coordination

Noxgild cloud services coordinate account authentication, computer identity, durable command records, approvals, wakeups or relay, usage accounting, audits, and permitted artifact delivery.

Worker routing

Capabilities are routed by namespace:

  • machine.* to the Machine worker,
  • browser.* to the Browser worker,
  • desktop.* to the Desktop worker.

The executor verifies that a capability is being handled by the correct worker.

Defense in depth

The computer does not blindly execute an arbitrary cloud instruction.

The local agent checks the capability catalog, security metadata, policy decision, worker mapping, and command lifecycle before handling a queued command.

On this page