Skip to content
Torch
Product Resources Docs Changelog Pricing Download
WINDOWS 10/11 Join the Beta

LEGAL

Security practices

Authenticated Bridge, least privilege and explicit confirmations.

Updated September 6, 2026Effective September 6, 2026

LEGAL

How it works in Torch

01

Threat model and least privilege

Torch assumes terminals and agents can execute commands with Windows user privileges, so it separates UI, preload and main process and reduces privileged surfaces.

02

Renderer and main-process isolation

Renderers use sandboxing, context isolation, disabled Node integration and web security. Production fuses block RunAsNode, Node options and CLI inspection.

03

Authenticated Bridge and path validation

The Bridge requires an authenticated session; IPC validates contracts and paths. File, Git, worktree and environment operations do not receive unrestricted renderer authority.

04

Destructive-action confirmation

Deletion, restore, worktree and other material actions require native or contextual confirmation. The app does not request elevation or install drivers or services.

05

Diagnostics, updates and reporting

Diagnostics remove secrets and workspace data; updates require signed artifacts and qualified rollback. Report vulnerabilities privately to security@torchorchestrator.com.

Explore more

↗Privacy policyLegal↗Torch Preview TermsLegal↗Third-party software and servicesLegal
Torch Orchestrator

Torch Preview · Invite-only Beta

© 2026 Torch Orchestrator

ProductCanvasMaestroFloors 3DDevice Portal
ResourcesDocsChangelogBetaSupport
CompanyAboutPricingDownload
LegalPrivacyTermsSecurityThird parties