> ## Documentation Index
> Fetch the complete documentation index at: https://docs.glasswarp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Safety and consent

> Consent, observability, encryption, and what Glasswarp can and cannot see.

Glasswarp drives a real machine, so consent and observability are built into the
platform — not left to the agent. Glasswarp provides the **controls**; you remain
responsible for your agent's **behavior**.

## Per-rig consent

API access is **off by default**. The rig owner must explicitly enable
`api_access_enabled` in **Console → Rigs**. No session can route to a rig
without it.

```python theme={null}
rig = next(
    (r for r in gw.list_rigs() if r.online and r.api_access_enabled),
    None,
)
```

## Visible session indicator

While an API session is active, the host shows an on-screen **"API session
active"** indicator on the real machine. The owner always sees when an agent has
eyes and hands.

## Kill switch and safety\_restore

The owner can end any session from the host or Console. On **every** exit path —
disconnect, launch failure, and API `END_SESSION` — the host runs
`safety_restore` to return the machine to a safe state.

## Audit log

Every API session creates an audit row (who, when, which rig, session duration,
action counts). Sessions are observable live via
[Live View](/guides/live-view) and after the fact via the Console.

## Privacy and data flow

Glasswarp is the transport between your agent and a Windows PC you own. Be clear
about what travels where.

### What is encrypted today

| Path | Encryption | Who can see content |
| - | - | - |
| REST API (screenshot, observe, input, session) | TLS to the API gateway; WSS to the host | The **API client** and the **rig**. The Glasswarp gateway **relays** these payloads transiently to fulfill the request. |
| Live View (optional WebRTC) | DTLS-SRTP media | The **viewer you authorize** (typically the rig owner in Console). Glasswarp signaling handles offer/answer and ICE — not media frames. |

### What we store

* **Stored:** account identity, API key hashes (not plaintext keys), session
  metadata and metering (start/end, minutes, action counts), audit rows, billing
  records.
* **Not designed as a recording product:** screenshot JPEG bytes and input
  event payloads are handled to complete the API call. They are not written to a
  customer-facing screenshot archive.

### UIA text in observe

`observe` (and `/targets`) can return structured UI Automation text alongside
or instead of a JPEG: focused window title/role, click-target names/roles, and
optional field values. That text is far easier to log, cache, and leak than
pixels — treat it carefully in your own systems.

| Field | Returned? |
| - | - |
| Window title / role | Yes |
| Target name / role / focus | Yes |
| Edit / field **values** | Yes for ordinary fields (truncated) |
| **Password / masked** fields | Role and name only — value always `[redacted]` (`masked=true`) |

Never rely on the platform to scrub secrets from screenshots; pixels can still
show masked dots or adjacent labels. Do not put passwords in prompts.

<Warning>
  Honest model for v1: the REST control plane is an **authenticated relay**, not
  application-layer end-to-end encryption. Glasswarp infrastructure can
  technically access those bytes while serving the request. Do not treat the
  screenshot/input API as “Glasswarp can never see your screen.”
</Warning>

### Who can watch Live View

Live View is for **humans you authorize** (rig owner / console session), not a
back-office feed for Glasswarp staff. Opening Live View is an explicit console
action on a session you own.

### Longer-term privacy

The product direction is a privacy model where **plaintext screenshots and input
are not readable by Glasswarp** (for example WebRTC / DataChannel control, or
application-layer E2E), matching Live View’s media encryption. Until that ships,
use the table above — not marketing shorthand.

## What's yours vs ours

<Columns cols={2}>
  <div>
    **Glasswarp provides**

    * Consent gate (per-rig API access)
    * Visible indicator
    * Owner kill switch (console session end + host tray **End API session…**; remote input blocked during tray confirms; Unpair disabled while a session is active)
    * Audit log + Live View
    * TLS / WSS in transit; WebRTC media encryption for Live View
    * Key scoping and rate limits
  </div>

  <div>
    **You are responsible for**

    * What your agent decides to do
    * Prompts, guardrails, and human-in-the-loop (HITL) review in your app
    * Not exfiltrating or misusing screen contents
    * Windows licensing and physical/cloud host security
  </div>
</Columns>

<Note>
  Glasswarp is the safe, observable I/O layer — not an AI-safety layer for your
  agent's decisions. Design your own review and approval flows on top.
</Note>

## Next: safe agent sessions

For a practical checklist (dedicated rigs, HITL, allowlists, budgets) — the
decision-layer playbook that sits on top of these controls — see
[Safe agent sessions](/guides/safe-agent-sessions).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.