Trust and limitations
Read this before connecting your accounts or using your assistant.
Operator access and isolation
The operator can access tenant data, including conversations, files and connected-account state. Encryption does not exclude the operator. Each tenant has dedicated containers, storage and restricted network access; these are the security boundaries. Managed configuration is advisory, and the current host uses the runc container runtime.
Connected accounts and browser login
Model tokens, WhatsApp device credentials and browser cookies are sensitive tenant state. The agent can use and potentially read its connected accounts and their saved authorization. Do not assume passwords or account secrets are inaccessible to it.
Manual browser login stops agent execution and scheduled jobs. Password saving is disabled; the platform does not log keyboard input or record login sessions. Close the viewer and explicitly resume when finished. The authenticated browser remains accessible to the agent afterward.
Unofficial WhatsApp
Hermes uses an unofficial bridge that is not supported by WhatsApp. WhatsApp may restrict or suspend your account, change its protocol or require pairing again. Using your own self-chat does not remove these risks.
Provider access and limits
Your model provider controls account access, usage limits and billing. ChatGPT subscription login does not provide API credits or unlimited usage. Provider restrictions, outages or authorization changes can interrupt tasks and routines.
Website sessions and reconnects
Website sessions can expire or be revoked. Websites may require another login, multi-factor authentication or restrict automation. Permanent login and successful automation on every website are not guaranteed. Reconnect through the website setup pages when your model, WhatsApp or browser connection needs attention.
Backups and recovery
Backups and exports contain credentials; protect them like account access. Encrypted off-host backups and a same-host disposable restore have been verified. Recovery may require reconnecting accounts even when saved data restores correctly. Restored identities and routines must not run alongside the original instance.
Clean-host recovery has not yet been verified. The six-hour recovery-point and four-hour restoration objectives are targets, not guarantees; obtaining replacement hardware and reconnecting accounts can add time. External launch remains gated by recovery and the complete customer journey.