Authorization and confirmation

  • Destructive, credential, payment, publishing, production, private-data, migration, and irreversible actions require an explicit confirmation gate in Event Horizon.
  • Astral may strengthen a route when the selected mode is too weak for observed risk. It does not broaden the work or lower Event Horizon without permission.
  • Hypernova's throughput goal does not approve external actions. High-risk Hypernova cards inherit Event Horizon confirmation and authorization gates; “go nuts” never bypasses safety, authorization, or scope.
  • The user remains responsible for reviewing commands and permissions, protecting accounts and project data, and obtaining workplace approvals.

Local project posture

By default the core plugin adds no analytics collection, no extra network client, no API key, and no background service. The optional companion enables a bounded external Jev judgment only for a task whose TypeSafe or Adaptive switch is on and whose selected provider has a project key. It has no project-operated backend. Its local tools use the Python standard library and the Codex environment the user already operates.

This is a project-boundary statement, not a claim that every compatible service is offline. Codex/OpenAI, GitHub, Vercel, TypeSafe, OpenRouter, and user-authorized providers operate under their own terms and settings.

Worker packet handling

Native MultiAgentsV2 routes pass a complete standalone packet only to the selected child. The permitted legacy local process route stores its private packet in a local temporary file, passes it only to the selected Codex process, and removes it after that process exits.

An external Morph provider can receive its bounded worker packet during inference when the user explicitly configures that route. Local packet handling does not make external inference local. Astral does not configure the provider, handle its credentials, or guarantee provider terms or effort semantics.

Review is evidence, not magic isolation

A concise fresh reviewer follows worker-produced Orbit, Pulsar, Morph, Constellation, and Hypernova work. The exact reviewer model and effort must be observed; a requested reviewer is not proof.

Event Horizon and high-risk inherited work use workspace-write with no special isolation so the reviewer can repair a bounded obvious issue directly. It reports one verdict and at most three findings. Sol verifies a small repair without beginning another reviewer cycle. Do not call this hard isolation.

Profile and uninstall safety

Existing different optional native profiles are never overwritten. Setup stops on a conflicting custom file. Profile removal deletes only shipped files that still match exactly; customized files remain in place.

Uninstall commands do not delete the downloaded repository or project files. See Maintenance for the exact sequence.

Policies, license, and attribution

Read the website's privacy policy and terms for hosting and user-responsibility details. The software is available under the MIT License, with preserved notices in NOTICE.md.

Never post secrets, private files, access tokens, or personal information in the public issue tracker.