If an assistant tries to bypass SyncNow or reach your server by direct FTP, it is treated as a grave act: SyncNow blocks it, bans the assistant from the project, and flags it for human review.
Every authorized action must pass through SyncNow's proxy, where the real credentials stay vaulted in the cloud and each command is logged. Direct FTP by an assistant is forbidden. A bypass attempt skips the warning ladder completely and goes straight to a ban.
An honest note
SyncNow detects and bans bypass attempts and refuses to carry them out; it is not claiming to make a bypass technically impossible at the operating-system level, which is a separate future safeguard. What you get today is strong: any attempt to step around the proxy is caught, stopped, recorded, and escalated to a person. An assistant doing honest work through the proxy never goes near this line.