Security
Four layers run on every operation: validate the input, gate the capability, track the budget, encrypt the wire.
| Page | Job |
|---|---|
| VAF | Input validation firewall (types, lengths, traversal, shell chars) |
| Sandbox | Capability gating: what an agent process may do |
| Escrow | Operation budgets and spend tracking |
| Encryption | AES-256-GCM, HMAC tokens, RSA primitives |
| Environment & Limits | Env vars, quotas, and hard ceilings |
| Airgap Propagation | Moving brains across air gaps via images |
| Best Practices | Safe setup guide for agent workflows |
| Privacy | What Vant stores, sends, and never sends |
The chain in one example
vant secret set github <value> # secrets never print to stdout
vant sandbox status # check what this process may do
vant sudo --status # check elevation state
Write paths validate input (VAF), check capabilities (sandbox), and honor budgets (escrow) before touching disk. The same chain guards the MCP surface and the headless server.
Where to start
Hardening a self-hosted or multi-agent deployment: Best Practices first, then Environment & Limits for the env vars that tune each layer. Understanding a specific refusal or block: find the layer above and read its page.
Related
- Configuration - Config keys including MCP auth
- CLI Reference -
secret,sandbox,sudo,encrypt