Security
Security at boxes.dev
boxes.dev runs real development environments for coding agents, so we treat security as a core part of the product. The product is built by seasoned software engineers who have shipped software used by some of the world's largest enterprises and previously worked on world-class engineering teams, including Facebook. You can read more about the team on our About page.
Credential guidance
We always recommend thinking carefully about which security keys and environment variables you upload to boxes.dev.
- Scope development credentials to the bare minimum required for the work you expect an agent or remote machine to perform.
- Do not upload environment variables or keys that grant access to production data.
- Prefer development, staging, sandbox, or read-only credentials when those are enough for local development and testing.
- Rotate or revoke credentials when you no longer need them on a remote machine.
Security Vulnerability Disclosure Policy
We welcome reports from security researchers acting in good faith.
Scope
- In scope: boxes.dev domains, the boxes.dev web app, desktop app, mobile app, CLI, public APIs, and hosted remote-machine management surfaces owned by boxes.dev.
- Out of scope: social engineering, physical attacks, spam, denial-of-service, attacks against third parties, and accessing or modifying data that is not yours.
Rules of engagement
- Do not access, modify, or delete data that does not belong to you.
- Do not degrade or interrupt our services.
- Do not use automated high-volume scanning without permission.
- Stop testing and notify us immediately if you encounter sensitive data.
- Give us reasonable time to investigate and remediate before public disclosure.
How to report
Email security@boxes.dev.
- Affected URL, endpoint, or product.
- Steps to reproduce.
- Impact.
- Proof of concept, if safe to include.
- Your contact information, if you want follow-up.
What to expect
- We will acknowledge receipt within 3 business days.
- We will investigate and may ask for more information.
- We will work to remediate validated issues based on severity.
- We do not offer a bug bounty unless explicitly stated.
Safe harbor
If you make a good-faith effort to comply with this policy, we will not initiate legal action against you for your research. If legal action is initiated by a third party, we may make it known that your actions were conducted pursuant to this policy.
Public disclosure
Please do not publicly disclose an issue until we have had a reasonable opportunity to fix it, typically 2 weeks, unless we agree otherwise.
Contact
For security review requests or vulnerability reports, email security@boxes.dev.
