Identity
Verify the workload
Establish the principal and session through a trusted identity source. Reject expired, revoked or mismatched context.

Zero trust
Zero trust informs how we are building AI security: verify identity, limit permissions and reassess authority at the boundary where an action occurs.
The work
Treat AI-generated content as input to the security decision. It cannot grant itself permissions or approve its own work.
Identity
Establish the principal and session through a trusted identity source. Reject expired, revoked or mismatched context.
Least privilege
Use an explicit environment, resource, action and model version. Ambiguous grants and missing evidence must deny a new proposal.
Human control
Keep approval separate from the proposing workload. Tie it to the exact action and policy, with expiry and revocation.
Development status
The product is in private development. App access and live security enforcement are not available.
What comes next
The private core is one component. A live security system also needs trusted context, controlled dispatch and operational testing.
Integration
An identity or attestation adapter supplies verified context. A request body cannot assert that a workload is trustworthy.
Execution
Recheck the current policy and consume approval atomically before dispatch. A previously returned permit is not a reusable execution token.
Operations
Define outages, revocation, safe operating boundaries and independent controllers with the system owner.