Security

Trust is a boundary, not a badge.

Source stays local by default, writes require authorization, evidence is signed, and failed checks never become verified.

Every boundary is explicit.

The hosted service coordinates policy-approved metadata. It does not receive source merely to simplify orchestration.

01

Data boundary

Only policy-approved metadata and evidence leave the customer environment.

02

Authorization

Least privilege, explicit write approval, OIDC workload identity, and mTLS options.

03

Supply chain

Signed capsules, provenance, expiry, revocation, and fail-closed validation.

04

Verification

Customer builds, tests, type checks, and policy determine success.

05

Deployment

Hosted, customer-VPC, self-hosted, and disconnected boundaries.

06

Disclosure

Private vulnerability reporting will be enabled before the open-core release.

Make the next change survivable.

Start with the local engine. Connect the network when it creates value.

Start building