Skip to content

FAQ

Common questions about OpenSyber, TokenForge, security, and compliance.


How do I secure my AI coding agent?

OpenSyber governs AI-assisted engineering through configured isolated workspaces, encrypted credential storage, policy decisions for governed tool calls, and documented skill verification. It supports selected Cursor, VS Code, Claude Code, Windsurf, and MCP-compatible workflows; event coverage depends on the integration. Setup time depends on deployment configuration.

What is the best tool for AI agent security?

OpenSyber focuses on runtime governance for AI-assisted engineering. Unlike general cloud security tools, it combines workspace context, policy decisions for governed agent actions, a documented skill workflow, and evidence exports for security review.

How do I prevent session hijacking in my web app?

TokenForge helps resist session replay by binding a session to a device key using ECDSA P-256 keypairs generated in the Web Crypto API. The private key is non-extractable in supported browser flows. Deployers must still protect the browser, account, and surrounding application.

How do I make AI agents compliant with SOC2 and ISO 27001?

OpenSyber provides control mapping and evidence workflows for SOC 2, ISO 27001, NIST AI RMF, GDPR, and the EU AI Act. These mappings do not certify OpenSyber or make a customer environment automatically compliant. Use the dashboard to review configured controls and export the evidence supported by the deployment.

What AI agents does OpenSyber support?

OpenSyber supports documented Cursor, VS Code, Claude Code, Windsurf, and MCP-compatible workflows. Additional agents can be connected where their tool and workspace traffic can be routed through a supported integration. Coverage depends on the deployment and integration path.

What is the OASF framework?

OASF (Open Agent Security Framework) is an OpenSyber-led framework with 15 proposed controls for AI agent governance, organized into Identity & Access, Runtime Security, Data Protection, and Governance categories. It is a control-mapping aid, not a certification standard or legal compliance determination.

How do I encrypt credentials used by AI agents?

OpenSyber provides encrypted credential storage at rest and a supported runtime injection path for configured agent containers. Access logging and rotation behavior depend on the deployment and integration. Customers should validate process, crash-dump, host, and egress exposure for their environment.

How does the free plan work?

The free plan includes the limits and integrations shown on the current pricing page, plus the dashboard and available local tooling. Retention, marketplace availability, and workspace limits vary by plan. No credit card is required for the free plan.

What are device-bound session tokens?

Device-bound tokens are session credentials that are cryptographically tied to a specific device. TokenForge implements this using ECDSA P-256 keypairs where the private key is generated as non-extractable in the browser's Web Crypto API. Even if an attacker steals the session token, they cannot use it from another device because they lack the private key needed to sign the challenge-response.

Can I embed a security badge in my README?

Yes. Every OpenSyber instance gets a public trust page and an embeddable security badge showing your current score. Go to Settings to get markdown or HTML embed code. The badge updates automatically and links to your public trust page — it serves as a viral growth loop for your project's security credibility.

What compliance frameworks does OpenSyber support?

OpenSyber offers evidence and control mapping workflows for SOC 2, ISO 27001, ISO 42001, NIST AI RMF, GDPR, and selected AI-governance requirements. OpenSyber is not formally certified, and a mapping does not establish legal compliance. Customers must validate scope, operation, retention, and audit requirements with their own reviewers.

Still have questions?

Email support@opensyber.cloud — response within 24 hours.