04 / SECURITY

Your agents
work where
your code
already lives.

Run an owned DAVE runner on Windows, macOS, Linux or your VPS. Your AI credentials stay there; the runner connects out and nobody connects in.

Request early access YOUR MACHINE / YOUR AUTH / OUTBOUND ONLY
THE TRUST MODELOrchestration without AI credential custody
01NO TOKEN CUSTODY

AI credentials stay local

Your AI provider or local model sign-in stays on the owned runner. DAVE sees which tools are available, never the tokens or authentication files behind them.

02OUTBOUND HTTPS

Runners are outbound-only

Your desktop or VPS opens no inbound port. Its runner asks DAVE for work over HTTPS, sends sanitized progress and returns the result.

03AES-GCM

Shared integrations are auditable

Connections such as Jira, GitHub and deployment providers are encrypted, versioned and auditable, with safe activation and rollback.

04LEAST AUTHORITY

Watching is not changing

Visibility and source-changing authority are separate powers. Every sensitive action checks the person, current state and approved plan before it runs.

THE HUMAN BOUNDARYAutomation stops on purpose

Around-the-clock
does not mean
automatic
production.

01

A human approves the exact scope before work starts.

02

DAVE runs the approved work and verifies the matching staging build.

03

A human tests reality and owns the production decision.

YOUR CODE / YOUR AUTH / YOUR BOUNDARY

Bring one real feature. See how far it moves without you.

Request early access