Workcell
Security and responsible reporting
Project boundaries, private credentials and explicit review are part of the workflow.
Customer access
Provider keys remain server-side. Customer packages must not contain developer Codex accounts. Sandboxed work is separate from the trusted project; approval does not grant physical robot access.
Report a vulnerability privately
Submit a short description through Support and retain the private reference. Do not include exploit payloads against real systems, credentials or customer data. Ask for an appropriate exchange method before sharing sensitive details.
Release integrity
Download only manifest-listed artifacts and verify hashes and Windows signatures. Public release remains gated until current platform and service qualification is complete.