SECURITY OVERVIEW
Security at
the execution boundary.
Start with the controls actually present in the source, then evaluate the environment in which they will operate.
Governed paths define coverage
gove-zone places verification before registered tool execution on integrated paths. It does not contain the host, authenticate every external identity, or prevent a tool from being called outside that integration.
Use the documented boundary and integration matrix to determine what the component covers in your workflow.
Read the enforcement boundaryControls the operator supplies
- Identity and authority
- Authenticate principals and map them to the roles and scope the integration uses.
- Trusted keys
- Configure signer and verifier trust, key custody, distribution, and the supported revocation behavior.
- Execution and storage
- Wire the executor, configure consumption when required, and anchor retained audit state independently.
- Operations
- Review the deployed headers, access controls, monitoring, recovery process, and required independent assessments.
Report a suspected vulnerability
The source lists security@acgs.ai as the security contact. Include the affected component, version or commit, observed impact, and enough context for the maintainer to understand the report. Keep credentials and sensitive customer data out of the initial message.
This website does not claim a response SLA, completed penetration test, or certification.
Review the current evidence
The original security page is an engineering draft that separates local configuration from live deployment proof. The product evidence index preserves known failed and missing CI results. Stronger assurance claims need evidence for the actual release and environment.
Inspect current product evidence