← CICDee

Security and safety model

Control plane and execution plane are separate

CICDee stores deploy intent and evidence. Windmill or an installed runner performs host-side execution.

Private-network friendly

The preferred path is private runner or agent execution. Public SSH is not the default architecture.

Safe command policies

Dangerous hooks are detected before save, destructive commands are blocked, and tokens/passwords/private material are redacted in UI output.