Try the demo

Trust

Security

What agents can do through DMN, what needs your approval, and where DMN's protection ends.

The engine only listens on your machine

The engine accepts connections from your own computer only; nothing on your network or the internet can reach it. The proxy and the app's own local interface listen the same way, and the terminal host talks to the app over a local pipe.

A few operations need a key as well: approving an agent's edit or command, deleting a project's index, changing the engine's model settings and shutting it down. DMN's app and command line read that key from DMN's data folder; agents talking to DMN over MCP never get it. It isn't a wall against programs running as you, which can read your files anyway.

What agents can do through DMN

What Allowed Needs you
Search and read the project's code Yes —
Read, write and delete the project's notes Yes —
Claim files they're about to edit Yes; claims are advisory and never block anyone —
Post to-dos and steps on the board Yes You decide what to do with them
Edit a file through DMN's edit tool — Each edit waits in the Fleet panel until you click Approve once or Reject
Run a command through DMN's run tool — The same, unless the project runs commands in the WSL jail
Open, fork, message, interrupt and close other agents' panes Yes, by default Agent autonomy can make each one ask you first
Start a headless teammate Yes, by default The same setting; Guarded asks, because a teammate runs with its permission checks off
Schedule an automation Yes, by default: it goes live when they add it Under Manual, or if you set it to ask, you arm it in the Automations tab
Open a page in DMN's browser Local dev servers The app asks you before an agent opens another site, runs script on it or reads its requests; headers that carry sign-ins are removed

Agent autonomy has limits that apply whatever you pick: at most eight agents that agents started running at once, at most 20 turns an hour from one agent to any one pane, and, if you set one, a daily budget for each automation an agent arms. Only you answer what an agent asks, never another agent. The setting is saved in your own config.toml, so a project can't change it.

The WSL jail

Settings ▸ WSL jail turns it on per project. Commands agents run through DMN's run tool then execute in Linux over a copy of the project: no network, no access to the rest of the disk, and their file changes are thrown away and listed. Because nothing they do can stick, they need no approval. Agents keep changes by editing files directly.

What DMN doesn't control

Your agents' own tools aren't DMN's. Claude Code's shell and file edits, and Codex's, follow each agent's own permission settings, whether the agent runs in a DMN pane or not. DMN doesn't sandbox them. Set those permissions in the agent itself.

Agents you start in the app run under a permission profile. Standard, the default, keeps the agent's own prompts, and DMN refuses a short list of dangerous commands sent to the pane's terminal. Autonomous starts the agent with its own prompts switched off (Claude Code's --dangerously-skip-permissions, for example) and lifts DMN's list too, so pick it only for work you'd let run unwatched.

DMN's notes are written by agents, so read them like any other text an agent wrote. A briefing marks a note whose code has changed since it was written.

Secrets

  • The records DMN keeps of past sessions, and the copies of tool output the proxy keeps, have secrets DMN recognises removed before they're written: API keys in the common formats (Anthropic, OpenAI-style, AWS, GitHub), bearer tokens, and values assigned to names like password, secret, token or api_key.
  • An API key you enter in Settings ▸ Memory goes in a key file in DMN's data folder, never in a settings file a project could commit.
  • Privacy and network lists every connection DMN makes.

Signed installs and updates

The installer is signed by Gelin Software; Windows shows the signature under Properties ▸ Digital Signatures. Every update is signed with DMN's release key, and the app refuses an update whose signature doesn't match. The download page shows each release's SHA-256.

Report a security problem

Email support@getdmn.com with what you found and how to reproduce it. Please give us a chance to fix it before you publish.