> ## Documentation Index
> Fetch the complete documentation index at: https://modal-devin.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Security model

> Credential boundaries, workload capabilities, and deployment guidance.

`modal-devin` reduces where long-lived credentials appear and fails conservatively
when it cannot establish a safe session state. An arbitrary session workload can still
use its assigned Outposts capability.

## Devin credential handling

The generated Modal functions receive the configured
[Secret](https://modal.com/docs/guide/secrets) and use it for all queue API calls —
claiming, status checks, and release. Those calls happen in the Modal function
process, outside the Sandbox that runs the session.

The Sandbox itself never receives the service user token. The claimed session is
handed to the Devin CLI with a short-lived, session-scoped connect token, which is
the only Devin credential the session workload can reach. Compromising a session
therefore exposes that one session's connection, not the queue-wide credential.

* Use a dedicated Enterprise service user with only the Outposts scopes
  (`account.outposts.machine`, plus `account.outposts.orchestrator` where outposts
  are created or deleted), and set an expiration.
* Separate outposts and credentials for different trust environments.
* Limit the session workload to credentials required for its work.

## Token handling during setup

The interactive setup:

* Prompts without echo.
* Avoids placing the token in subprocess arguments.
* Stores it in a named Modal Secret when approved.
* Excludes it from the generated application.

Avoid supplying tokens directly in shell commands, checked-in files, or clone URLs.

## Network model

The Devin worker initiates outbound connections to Devin Cloud. No inbound port or
public IP is required. Apply Modal's
[Sandbox network controls](https://modal.com/docs/guide/sandbox-networking) to any
internal services the session is allowed to reach.

## Recovery behavior

When final session state is unavailable or unrecognized, `modal-devin` treats the work
as incomplete. It attempts to preserve the filesystem and reports a
failure so the condition remains visible to monitoring while the durable recovery
snapshot remains available to a later claim attempt.

## Supply-chain considerations

Worker images install the Devin CLI and other selected tools during the trusted image
build. Review build output, restrict who can change image definitions, and follow
project releases for dependency and compatibility updates.

## Report a vulnerability

Use [GitHub private vulnerability reporting](https://github.com/aaazzam/modal-devin/security).
Exclude live Devin, Modal, and repository credentials. Include the affected
version, reproduction steps, expected impact, and whether a credential or workload
may have been exposed.
