VOOLDocs

Security model#

Boundaries#

  • The workspace bounds file access. Outside it, the runtime cannot read or write.
  • The credential store holds keys. Keys are not written into config files or logs.
  • Tool confirmation bounds changes. Modifying actions ask before running.

Keys#

Your provider key is stored by the operating system — Keychain, Credential Manager, or Secret Service — and used from your machine to reach your provider. It is not sent to Parad0x Labs, and there is no Parad0x-operated endpoint in the request path.

Plugins#

A plugin runs with the runtime's access. That is what makes plugins useful and what makes them worth reading before installing. See Skills and plugins.

Reporting an issue#

Send security reports to [email protected]. Include the version, the platform, and the steps to reproduce.

Current builds are closed-test and unsigned; the macOS build is not notarized. See Release status.

VOOL — Parad0x Labs · 2026