Security architecture
Useful access.
Explicit boundaries.
Donatello is an agent with tools, so its permissions must be visible, limited and reversible.
Project boundary
The Windows Agent validates every path and works only inside the selected project folder.
Protected credentials
External API keys are encrypted with Windows DPAPI, injected into the worker process in memory and never written to project files or logs.
No inbound port
The Windows Agent makes outbound provider and account requests. Donatello never exposes a listening port on the user's router.
Revocable sessions
The Windows Agent uses short access tokens and a revocable device session tied to the Donatello account.
Visible permission decisions
When work needs access beyond ordinary project editing, Donatello asks the user to reject it, allow it for the current task or remember that type of permission. A task can always be stopped from the interface.
Local work stays local
File editing, commands, previews and video rendering happen inside the Windows Agent and its selected project folder. Donatello services are contacted only for clearly identified account, AI or media operations.
Report a problem
Security reports can be sent to hola@abrahamaragon.com. Include the Agent version and a reproducible description; never include an API key.