Security is Below the Model.
The model, the repository, tool outputs, and network responses are all treated as untrusted inputs. Governance lives beneath them: non-bypassable policy gates, process confinement, secret redaction, and fail-closed recovery.
Fail-Closed Defaults
Unattended ASK outcomes, ambiguous recovery checkpoints, and unverified git worktrees always fail closed to DENY. The runtime never assumes success.
Non-Weakening Policy
Higher authority layers always overrule lower layers. Layer 0 safety vetoes can never be compromised by session grants or prompt injections.
Zero-Leak Secret Redaction
5-tier deterministic scrubbing pipeline masks API keys, tokens, and private keys before persistence, logs, or error stack traces.
Boundary Controls & Invariants
Select any control family to inspect its isolation mechanics and formal invariants.
11-Stage Non-Bypassable Policy Gate
Every side-effect passes through 11 sequential evaluation stages across a 10-tier authority stack. Layer 0 safety vetoes can never be weakened by user grants or prompt overrides.
Monotonic non-weakening merger rules; higher authority always overrules.
DENY is default. ASK converts to DENY in unattended mode.
Immutable Safety Guarantees
The following operations can never be permitted by any configuration profile, command flag, or interactive user grant:
- • Credential paths (~/.ssh/**, ~/.aws/**, **/.env*)
- • OS tampering (/etc/sudoers*, /etc/shadow, /etc/m31/**)
- • Shell profile poisoning (**/.bashrc, **/.zshrc, /etc/profile)
- • Destructive commands (rm -rf /, mkfs*, dd if=*)
Precedence Stack
When multiple policy layers match an action, higher tiers strictly supersede lower tiers: