20131 20131
中文

Security boundaries AI cannot decide

Priority stack

System Security Boundary→User Hard Deny→User Explicit Policy→Task Capability→Adaptive Policy→Default Policy

AI can never bypass the System Boundary, User Hard Deny, core Anti-Tamper, or the Recovery Boundary. The security boundary is not a negotiation with the model.

Local Core First

Core security keeps running when the API expires, the cloud is down, the model is unavailable, the network drops, or the subscription server fails. The cloud is an extension, not a security dependency.

Privacy stance

The runtime analyzes locally. Audit history stays on your machine unless you explicitly opt in to cloud analysis. The product never needs your prompts, and the Security Map is designed so it cannot be turned into a treasure map by a compromised agent.

Honest limitations

Foundations in design: pre-action enforcement, supply-chain and skill/MCP analysis, prompt-injection-resistant policy inputs (model output never widens its own grants), and anti-tamper. Design details are published in the security whitepaper as it matures.