Security
Last updated 2026-10-08
Bots that browse and use files need strong walls around them. This page describes the controls Ruvio really has today, in plain words. We are a small team and Ruvio is in private beta, so we describe what exists and do not claim more.
Your own private computer
- Each person gets a separate private computer, a small virtual machine. Your bots, files and browser live there, not on a shared machine.
- The computer has no public SSH or open inbound access. Our server reaches it only through a dedicated key with a pinned host key.
- Inside it, each bot runs as its own Linux user with its own home folder, resource limits, temporary folder and browser profile.
- A firewall blocks the computer from private and local networks. It can reach only DNS and our AI gateway on the host, plus the public internet that the bot's task needs.
- Computers used through our partner API are stricter: the internet is switched off, and only the AI gateway and DNS can be reached.
Keys stay out of your computer
Our AI provider key is held by a gateway on our server. Your computer never sees it. It only gets short-lived, per-task tokens, and every request through the gateway is counted against your allowance.
Bots must ask before they send
- Before a bot sends a message, email, calendar invitation or post in a supported app, Ruvio shows you the exact text and waits for your tap. Nothing is sent without it. If you change the text or the recipients are different, nothing is sent.
- Bots type at a human pace, and there are limits on how many messages they can send per task and per hour.
Who can get in
- Ruvio is invite-only during the beta.
- You sign in with Google. We never see or store your Google password.
- Your session cookie is Secure, HttpOnly and SameSite, and it expires after 7 days. We store only a hash of it.
- The operator panel is on a separate address with its own login, checks against forged requests, and is not reachable from the product's address.
- API keys for our partner API are stored only as hashes, and each call is limited by scope and rate.
Data in transit and at rest
- All traffic to ruvio.site and chat.ruvio.site uses HTTPS (TLS) through Cloudflare. Our services listen only on the local machine and are reached through a Cloudflare tunnel.
- Our account database is readable only by the service account that runs Ruvio.
- Our web pages send security headers: a strict content policy, no framing, and no sniffing of content types.
- When you delete your account, we remove your data and your computer. See our Privacy Policy for what that covers.
What we do not claim
Ruvio has no security certification, such as SOC 2 or ISO 27001, and has not been through an independent audit. No system is perfectly safe. Bots can also be tricked by the web pages they read, which is why the approval step exists. Please check what you approve.
Report a vulnerability
If you find a security problem, please email [email protected] with the subject "Security". Tell us what you found, where, and how we can reproduce it. We will read it, reply and fix it as fast as we can.
Please:
- do not access or change other people's data, and use only your own account;
- do not disrupt the service (no heavy load or denial-of-service tests);
- give us a reasonable time to fix the issue before you tell others.
We do not run a bug bounty and cannot promise a reward. We will thank you if you want us to.