Skip to content

File Locations ​

Anything that runs as root — or that root is pointed at — is installed to a root-owned location, never under your home directory: a location you can write to is a location a compromised agent running as you can write to.

PathContentsOwner
~/.local/bin/sevorixThe daemon and CLIyou
/usr/local/lib/sevorix/Privileged binaries (sevsh, the eBPF daemon), sevsh's recorded SHA-256, and the verification scriptroot:root
/usr/local/bin/sevshPATH-visible symlink to the root-owned sevshroot:root
/usr/local/bin/sevorix-cgroup-helperPer-session process containmentroot:root
/usr/local/bin/sevorix-agent-launcherPrivileged agent sandbox launcherroot:root
/usr/local/bin/sevorix-agent-wrapPuts a launched agent's process tree in a Sevorix cgrouproot:root
/etc/sudoers.d/sevorix-*Passwordless invocation of the helpers above, if you accepted themroot:root
/usr/local/share/ca-certificates/sevorix-mitm.crtThe TLS interception CA, if you enabled TLS inspection and chose to trust itroot:root
/etc/sysctl.d/60-sevorix-userns.confThe user-namespace setting, if you accepted itroot:root
~/.sevorix/policies/Policy files (one .json per policy, or an array per file)you
~/.sevorix/roles/Role filesyou
~/.sevorix/settings.jsonDaemon settings — intervention, TLS, inbound scanning, experimental flagsyou
~/.sevorix/logs/Session traffic logsyou
~/.sevorix/models/Downloaded classifier modelsyou
~/.sevorix/integrations/Integration manifests and backupsyou
~/.local/state/sevorix/PID files and per-session metadata (including session tokens)you
~/.config/sevorix/hub_tokenSevorix Hub authentication tokenyou
~/.config/sevorix/policies.jsonLegacy single-file policy fallback, still loaded if no directory policies are foundyou

A known inconsistency

sevorix config check still reports on the older ~/.config/sevorix/ paths. The actual load order prioritises ~/.sevorix/; the migration is incomplete and the check's output has not caught up. Trust ~/.sevorix/ as the primary store.

Runtime containment for autonomous AI agents.