# Security

> How StellarFirm keeps your work safe: private workspaces, tokens that are never shown back, an allowlist for network access, and how to report a problem.

Your assistants can read your code and act on your accounts, so StellarFirm is built to keep each piece contained. This page lists the protections you can rely on and what you can do to help.

## Private workspaces

Each assistant works in its own workspace, a computer of its own. A workspace is private to your company and kept apart from every other workspace, including your other assistants'. One assistant cannot read another's files.

The Coder keeps your repository inside its own workspace. It does not work from a copy anywhere else.

## Tokens for integrations

To connect GitHub, GitLab, or Bitbucket, you create a token on that service and paste it into Integrations in the StellarFirm desktop app. [Connect your code](/docs/getting-started/connect-your-code) lists the permissions each step needs.

| Rule | What it means for you |
| --- | --- |
| You create the token | You choose what it can do. Give it only the access the Coder needs. |
| Kept on your computer | The desktop app saves it on your computer. It is not shared with anyone else. |
| Never shown back | After you save it, the screen only shows that it is connected. |
| Kept out of chat | Tokens do not belong in messages, briefs, or notes. |
| Sent only to the service | The Coder passes it to the one command that needs it, and does not leave it in your repository settings. |

> [!TIP]
> If you ever paste a token somewhere by mistake, rotate it on the service that issued it and save the new one in Integrations.

## Network access is limited

A workspace cannot reach the whole internet. Network access is limited to an allowlist of the places an assistant needs to do its job. Everything else is blocked.

## Sign-in is required

Every page of the app needs a signed-in account. If you open an app page while signed out, you are sent to the sign-in page first. See [Sign in](/docs/getting-started/sign-in).

## You approve the risky parts

An assistant cannot send, deploy, charge, publish, or create something on its own. Those steps wait for your Approve unless your house rules allow them. See [Approvals and control](/docs/trust/approvals-and-control).

## What you can do

1. Create tokens with the narrowest access that works, and use a separate one for StellarFirm.
2. Connect a test repository first, then a real one.
3. Keep [auto-approve](/docs/ceo/approvals#auto-approve) off until you trust a kind of step.
4. Review pull requests before they are merged.
5. Check [Memory](/docs/trust/privacy#memory) now and then.

## Report a security issue

If you think you have found a problem in StellarFirm, write to us through the [Support page](/support). Say what you saw, where, and how to reproduce it. Do not include tokens, passwords, or other people's data.

## Next

- [Privacy](/docs/trust/privacy)
- [Approvals and control](/docs/trust/approvals-and-control)

---

Source: https://stellarfirm.ai/docs/trust/security
