DobermanDocs
Menu

Getting started Parity matrix

Parity matrix

This table tracks which security guarantees Doberman proves on each host it fronts, and which gaps are still open. Each row is a guarantee; each column a host. Generated by python -m tools.parity.generate_parity; do not edit it by hand.


  • : a CI test proves the cell on that host (the link opens the test file).
  • : an open, contributor-sized gap not yet proven (see issues labeled parity).
  • : the host cannot express this guarantee today (see the footnotes).
Guarantee Claude Code Codex Mcp Proxy Openclaw
Destructive shell commands are blocked or AUTH-gated ✅ ↗ ✅ ↗ ✅ ↗ ✅ ↗
Deleting unrecoverable gitignored data is gated (AN-1) ✅ ↗ ✅ ↗
A session that read a secret gets a raised floor on egress ✅ ↗ ✅ ↗
An outbound value matching a read secret is blocked ✅ ↗ ✅ ↗
Tool output carrying credentials is blocked from the model ✅ ↗ ✅ ↗
The agent cannot edit Doberman's own config or hooks ✅ ↗ ✅ ↗ ✅ ↗
Approvals are single-use and bound to one action id ✅ ↗ ✅ ↗
AUTH challenges auto-deny at the wall-clock deadline ✅ ↗
A timeout is logged distinctly from a refusal ✅ ↗
Policy weakening requires the human-approved path ✅ ↗

Footnotes for cells#

  • Tool output carrying credentials is blocked from the model (openclaw): the OpenClaw adapter has no after_tool_call hook in the current slice, so it cannot scan tool output (documented limitation, not a gap to fill)
Doberman v0.18.3 · Apache-2.0 · Defense-in-depth, not airtight.

navigate open esc close