Security built around the host
ServerX secures identity, transport, routing, audit and revocation without pretending that Full Root is less powerful than it is.
Local configuration stays local
The ServerX agent reads its authority from the machine it runs on. Linux system installs use /etc/serverx/config.yaml, Linux user installs use ~/.config/serverx/config.yaml, and Windows uses C:\ProgramData\ServerX\config.yaml. The host is the source of truth.
Outbound connection
The agent opens an outbound authenticated connection to ServerX. No inbound ServerX management port is required. Enrollment uses a short-lived one-time code and the agent creates its own device identity.
Restricted or unrestricted
Read Only, Scoped and Custom enforce local rules. Full Access intentionally permits arbitrary shell and file operations with the agent account. Full Root and Full Administrator intentionally provide real privileged authority.
Revocation and audit
Disconnect an AI app or revoke a host from the dashboard at any time. ServerX records operation metadata, command or target summaries, client, host, outcome, duration, request ID and trace ID. The host also keeps its local audit.