Skip to content
RehearsalDocs

Security and trust

What a practice world can and cannot reach, how checks stay read-only, where keys and passwords are kept, and what an operator must do.

This page states what the product does, as the code of version 0.1.2 does it. Where something is not built or not decided, the page says so.

Your production systems

Rehearsal does not connect to your production systems. It needs three things from you, and none of them is access:

You giveRehearsal does
The address of a public git repository, and a commitFetches the source at that commit, to read it
The names of container images, with digestsPulls the images, to run them
Policies, in plain wordsTurns them into rules that jobs check

The data in a world is fictional. The World Compiler creates the customers, the records and the history. Do not put real customer data, real credentials or production addresses into an application or its policies: nothing needs them.

What a world can reach

Each world runs in its own sandbox: a set of containers that a worker starts and removes.

  • No internet. The application's containers are on an internal network with no route out. They can reach each other by name, and nothing else.
  • One guarded entrance. One container at the edge of the sandbox passes requests in. It accepts only requests that carry the platform's own token.
  • Outside services are emulated. Payments, shipping and email do not leave the sandbox. The emulator records each request, and checks can read that record.
  • Limits on each container. By default 1 GB of memory, 1 processor and 256 processes. The containers cannot gain new privileges, and a set of kernel capabilities is removed, such as raw network access.
  • A clean start for each episode. A reset removes the containers and restores every data volume from a saved snapshot. Nothing from one episode reaches the next.

An agent never talks to the application directly. Each action goes through a gateway that checks the actor's role before the call, validates the arguments, and adds the role's own credential. An agent does not see another role's credential.

How checks stay safe

A model writes the checks during a build, so the server treats every check as untrusted text.

  • A check is one statement. A second statement in the same query is refused, and so are client commands.
  • A check runs in a read-only transaction. On SQLite, an authorizer allows reading only.
  • Values are bound as parameters by the database client. They are not pasted into the query.

How scoring works explains how checks decide an outcome.

Keys, passwords and sessions

SecretHow it is kept
API keysThe server stores a SHA-256 hash and the 8-character prefix. The key is shown once, when it is created
Keys from rehearsal loginCreated at the moment the terminal collects them, and never stored in a readable form on the server. On your machine: one file that only your user can read
PasswordsHashed with scrypt and a salt for each account. At least 10 characters
Browser sessionsA signed cookie that lasts 12 hours. The signing secret is the server's REHEARSAL_SESSION_SECRET
Model provider keysIn the server's settings only. They are not sent to browsers, to agents or into worlds

Sign-in and sign-up requests are limited for each network address, to slow down guessing.

What a key can do

A key belongs to one project and has an access level. A key with "Build and evaluate" access cannot create keys or change billing. A key with "Read only" access cannot start anything. See Sign in and keys.

Revoking a key takes effect at once.

Secrets in records

The server keeps a record of each build and episode: the events you see in the console. Before text is stored, the server removes the values of its own secrets from it: every setting whose name ends in API_KEY, TOKEN, SECRET or PASSWORD, and text that looks like a credential.

What leaves the server

Goes toWhatWhen
Your model providerThe prompts of the World Compiler, the simulated customer and the agents: parts of the application's source, the fictional data, and the conversationDuring a build, a run, an improvement and a re-check
A tracing serviceTraces of the same callsOnly when the operator sets a tracing key. Off by default
A payment providerThe workspace owner's email address, the organisation's name, and what you buyOnly on a server with plans turned on, when you buy a plan or a top-up

The source of your application is sent to the model provider in parts, because the World Compiler reads it to build the world. If your source must not go to a model provider, run your own server with a model that you host.

AI assistants

An assistant that uses the Rehearsal plugin acts with your key and within its access.

  • It is told never to ask for a key in the chat, and never to print one.
  • It is told to state the cost and ask before each action that spends money.
  • The plan's limits and the monthly allowance stop a request whatever the assistant decides.

If you run the server

On your own server, these are yours to do.

DoWhy
Give Rehearsal a machine of its ownA worker controls Docker on its host, and runs images that applications name
Build only from sources and images you trustA world runs their code. For source from people you do not know, isolate each job in its own virtual machine
Set a long random REHEARSAL_SESSION_SECRETIt signs browser sessions
Set REHEARSAL_SIGNUP=closed on a server that strangers can reachSign-up is open by default, so any visitor can create an account and an organisation
Serve it over HTTPSThe Compose file's public profile obtains a certificate
Give the database its own role and schemaSome managed databases expose the public schema through an API of their own
List operator admins in REHEARSAL_ADMIN_EMAILS only when you need themAn operator admin sees every workspace. Only a sign-in with Google counts for this list

What this page cannot tell you yet

  • How long the hosted service keeps data, and how to ask for deletion. This is not defined in the product.
  • Compliance reports. None exist.
  • A security contact. To report a security problem, contact the maintainers privately. Do not open a public issue with the details.
Checked against rehearsal-kit 0.1.2 on 11 October 2026.

Was this page helpful?

Edit this page

On this page

Was this page helpful?

Edit this page