Security
Current security status and roadmap for Wendy and WendyOS
Security Overview
This page describes the current security posture of Wendy and WendyOS and what's coming next.
Access control and device enrollment are not yet available. Treat any reachable agent as accessible to any authenticated CLI on the same network or tunnel. Do not expose wendy-agent to untrusted networks until access control ships.
Current Status
| Area | Status |
|---|---|
| CLI-to-Agent communication | mTLS Authenticated |
| Data in transit | mTLS encrypted with Post-Quantum Cryptography |
| Cloud connectivity | Zero-trust — PKI authentication required |
| Device identity / Enrollment | Available |
| Access control | Nearing launch |
Security Roadmap
Project-Scoped Access Control
Granular control over who can deploy what and where. CLI instances and users will be scoped to specific projects and devices, so you can share a network without sharing access.
Reporting Security Issues
If you discover a security vulnerability, please report it responsibly by emailing security@wendylabs.com rather than filing a public issue. We take all reports seriously and will respond promptly.
Stay Updated
Security features will be announced on our blog and in our Discord community.