Security

Built to be transparent, scoped and reviewable.

AWMate follows a straightforward model: local execution, explicit approval, minimum necessary access. We do not claim certifications that NxtGenSec has not obtained.

Scoped file access

AWMate reads only inside the project folder you select. Switching or removing a project immediately revokes that access.

Command approval

Every terminal or build command AWMate wants to run is presented for your explicit approval.

Local execution

File reads, edits and command execution happen on your Windows machine. You control the environment.

Server-side credentials

Provider credentials required to power AWMate remain on the server. They are never delivered to the browser or the desktop client in plain form.

Change review

Code changes are always presented as diffs. Nothing is written to disk without your approval.

User responsibilities

You should review code and commands before running them in production. Treat AWMate as an assistant, not an unattended agent.

Report a security issue

If you believe you have found a security issue in AWMate, please contact NxtGenSec responsibly. Provide reproduction steps and any relevant version information.

Security contact: security@nxtgensec.org

This address is configurable and should be updated via environment configuration for production deployments.