cratoriumbeta
Safety

Generated code runs behind deliberate boundaries.

Cratorium combines isolated execution, private defaults, explicit spend limits, security gates, and an auditable agent timeline.

Isolated builds

Generated projects run through managed sandbox providers. The application host is not used as an execution environment for customer code.

Secrets stay separate

Project environment values are write-only in the Studio, encrypted at rest, and injected at runtime without being written into generated source.

Publish gates

High-severity static findings block sharing and deployment until they are repaired. Preview verification records whether the result actually responds.

Human control

Every agent turn has a declared credit ceiling, can be cancelled, and records its plan, actions, files, checks, and recovery events.

Community controls

Members can report posts and block profiles. Reports enter a durable owner moderation queue; community moderators can pin or remove posts and delete abusive comments.

Safer uploads

Room uploads have strict size and type limits, executable formats are blocked, declared media signatures are checked, and project-storage uploads bind type, length, and checksum into short-lived signatures.

Responsible disclosure

Report a suspected vulnerability privately through the support channel. Do not access data that is not yours, disrupt service availability, or test payment systems with real financial instruments.