Security & Verification

What we protect, what we don't, and how to independently verify outputs.

What we protect

  • Integrity of logged events (where applicable)
  • Verifiable fingerprints for outputs and exported artifacts
  • Clear trust boundaries between components and capabilities

Known limits

  • No system can protect against a fully compromised device
  • Verification requires running checks correctly
  • Some techniques evolve; we document assumptions and changes as they happen

Verification

Where verification is supported, outputs include fingerprints or proof records. You can validate integrity using standard tools and our reference workflows.

Verification guide →

Responsible disclosure

Found a vulnerability? Report it at . We'll acknowledge and coordinate a fix as quickly as possible.

Disclosure policy →

Audit roadmap

Third-party audits are considered as products mature. When audits occur, scope and outcomes will be documented here.