Security
Built to be transparent, scoped and reviewable.
AWMate follows a straightforward model: local execution, explicit approval, minimum necessary access. We do not claim certifications that NxtGenSec has not obtained.
Scoped file access
AWMate reads only inside the project folder you select. Switching or removing a project immediately revokes that access.
Command approval
Every terminal or build command AWMate wants to run is presented for your explicit approval.
Local execution
File reads, edits and command execution happen on your Windows machine. You control the environment.
Server-side credentials
Provider credentials required to power AWMate remain on the server. They are never delivered to the browser or the desktop client in plain form.
Change review
Code changes are always presented as diffs. Nothing is written to disk without your approval.
User responsibilities
You should review code and commands before running them in production. Treat AWMate as an assistant, not an unattended agent.
Report a security issue
If you believe you have found a security issue in AWMate, please contact NxtGenSec responsibly. Provide reproduction steps and any relevant version information.
Security contact: security@nxtgensec.org
This address is configurable and should be updated via environment configuration for production deployments.