Security and control
Letting AI act on real machines is only acceptable if you decide what it may do, sensitive steps wait for a person, and everything is on record. This page explains how LetKite does that today in LetKite Lite, and what LetKite adds.
Three limits on every command
A command runs only if all three layers allow it. Loosening one layer never widens the others.
Client scopes
When you connect an AI client you approve scopes: fleet.read, fleet.exec, fleet.write. Start with read and exec; withhold write until you need it.
Node scopes
Each machine has its own scopes, so a production database can be read-only while a staging box accepts changes.
Account rights
The gateway logs in to each node as a dedicated unprivileged account without sudo. Anything that needs root goes into an explicit sudoers allowlist.
Sign-in without shared secrets
AI clients never receive a password or an SSH key. They connect to the gateway with OAuth 2.1:
- Access tokens expire after 15 minutes and are bound to your gateway's URL.
- Refresh tokens rotate on every use; replaying an old one revokes the whole token family.
- Authorization uses PKCE (S256) and single-use codes that expire in two minutes.
- You approve each client on a consent page that shows where it will call back. Only allowlisted callback addresses are accepted.
- Admin passwords are hashed with scrypt, and repeated failures trigger an exponential lockout.
Confirmation for risky commands
Obviously destructive patterns — wiping the root file system, formatting disks, fork bombs — are refused outright. Commands that are legitimate but risky, such as a reboot, stopping a service, flushing firewall rules or a recursive delete, are held until the AI states the exact command and confirms it, so you see what will run before it runs.
These guardrails catch accidents, including a model misled by text it read. They are not the security boundary; the unprivileged node account is. For extra caution, run the gateway read-only or withhold fleet.write.
A record of every call
The gateway writes one line to its audit log for each call, flushed to disk before the result returns: who made the call, when, on which node, the command, and its exit code. Long jobs keep their output on the node, so you can read it after the fact.
Nothing installed on your servers
Linux nodes need no agent. Enrollment creates the low-privilege account and adds the gateway's public key; no code and no private key is placed on the node. Removing a node takes one command, and uninstalling the gateway removes its key from every node first.
Where your data goes
With LetKite Lite, the gateway runs on your own server. Commands and their output travel only between that gateway, your machines and the AI client you connected; LetKite, the company, does not receive them. The AI provider sees what its assistant reads and writes, under that provider's own terms.
Threats we design for
| If… | LetKite Lite responds with | What remains |
|---|---|---|
| Someone finds the gateway's address | Every endpoint needs a token or is public metadata; sign-in needs a password and locks out after repeated failures. | They can tell the service exists. |
| An authorization code is intercepted | PKCE, a two-minute single-use code, and replay revokes the token family. | — |
| An access token leaks | It expires within 15 minutes and only works against your gateway. | Usable inside that window. |
| A prompt tries to trigger damage | Guardrails, the confirmation step, withheld write scope or read-only mode. | Guardrails can be bypassed; account rights are the boundary. |
| The gateway itself is compromised | Sandboxed service, key readable only by the service account. | The gateway holds the key to every node. Protect it like a bastion host. |
Questions
Can the AI run any command it likes?
Only within three limits at once: the scopes you approved for the client, the scopes set for each node, and what the node's unprivileged account may do. Risky commands also need an explicit confirmation.
Does LetKite see my commands or files?
Not with LetKite Lite. The gateway runs on your own server; commands and their output pass only between that gateway, your machines and the AI client you connected.
Where is the audit log kept?
On the gateway, as one line per call. It records who made the call, when, on which node, the command and its exit code.
How do I report a security issue?
Email contact@letkite.com. Please include steps to reproduce, and give us a chance to fix the issue before disclosing it.