EKORD

Security

Execution model

The Agent runs as your local operating-system user and can do what that user can do: read and write files and run commands in that account.

Connection direction

The Agent makes an outbound connection to EKORD. Your machine does not need inbound firewall or NAT configuration.

What EKORD stores

What EKORD does not persist

Credentials and revocation

Each paired device holds its own credential. A device credential can be revoked server-side; after revocation the Agent is rejected and must pair again.

Tools

Stopping the Agent removes remote execution availability.