remoteagent.online  the open-source control plane for secure, cost-controlled AI agents

The security model - policy, grants, mTLS, hash chains

How RemoteAgent Online turns security from a promise into a configuration: four layers, each independently verifiable.

Updated 2026-08-24Reading time 5 min

Four layers

  1. Policy - deny, allow, ask, enforced on-device
  2. Grants - least privilege, time-boxed
  3. Transport - mTLS between device, relay and plane
  4. Log - hash-chained, anchored daily

Independently verifiable

Each layer can be checked without trusting the vendor: read the policy file, inspect certificates, verify the chain.

Threats covered

Prompt injection, key exfiltration, rogue agents, silent history edits and runaway spend - each maps to a control.

Next

Run the audit verification yourself.

RemoteAgent Online - 100 solutions · Blog · mona.expert · Sign in free