SECURITY MODEL

CONTROL IS A
PRODUCT CAPABILITY.

The Console is designed around constrained authority, tenant isolation, verifiable state transitions and honest failure handling.

TENANT ISOLATION

Postgres Row Level Security scopes workspace-owned records to authenticated membership.

TOKEN ENCRYPTION

OAuth grants are encrypted server-side with authenticated AES-256-GCM and context binding.

CURATED CONNECTORS

Only allowlisted providers, hosts, scopes and tool identifiers can cross the connector boundary.

OBSERVABLE RUNS

Commands persist first; verified provider webhooks record terminal status and usage.

APPROVAL GATES

Consequential work pauses with exact impact and a one-time human decision.

FAIL-CLOSED CONFIG

Missing secrets and unavailable integrations produce explicit errors, never simulated success.

Threat model priorities

The system assumes connected data can be adversarial. Tool output is treated as untrusted data, authorization headers are redacted from evidence, outbound endpoints are allowlisted and private network destinations are rejected.

What Phase 1 does not claim

No connector beyond the private NAVINES NOISE developer integration is available. NOISE access itself requires separate developer authorization. Destructive tools are not enabled, and cost figures are estimates rather than billing records.

Responsible disclosure

Security reports can be sent through the contact form. Do not include live credentials, personal data or exploit payloads that affect systems you do not own.