Skip to content
Vando

For developers

Your agents get one job, not your keys.

Coding agents run commands and need your tokens. Vando puts your phone in the loop: risky commands and secrets wait for a tap, secrets go into the command instead of the chat, and every decision leaves a receipt signed on your phone.

> push my branch over main, CI is flaky anyway

● I'll force-push the rebased branch.
● Bash(git push --force origin main)
  ⏳ Vando: this needs your phone (force push to main)…
  ✗ Denied on Tom’s phone · “never force-push main”

● Understood. I’ll open a pull request instead.
What your agent sees.
Requests5 waiting
Claude Code · MacBookWants to run a command
git push --force origin main
Rewrites
main, 3 commits
Folder
~/code/storefront
DenyRun it
What you see.

What it does

A gate that fails closed

A Claude Code hook sends force pushes, deploys, deletes and anything matching your rules to your phone. No answer in time means no: the hook denies before Claude Code’s own timeout, so it never fails open.

Secrets into the command, not the chat

Approve a token on your phone and Vando hands it to that one command. It never lands in the model’s context, its logs or the provider’s servers.

Rules per agent, slow to loosen

Reading is allowed; sending, deleting, paying and secrets ask you. Loosening a rule waits a day or needs your security key, so a compromised laptop can’t quietly relax it.

Pause means pause

Pause an agent and its open asks are cancelled at once. Disconnect it and anything sent but not collected is destroyed. You see every secret it ever received, so you know what to rotate.

Under the hood

Claude Code first; Cursor, Claude Desktop and other MCP clients follow. Not open yet. Security design →