SECURITY OVERVIEW

Security at
the execution boundary.

Start with the controls actually present in the source, then evaluate the environment in which they will operate.

Governed paths define coverage

gove-zone places verification before registered tool execution on integrated paths. It does not contain the host, authenticate every external identity, or prevent a tool from being called outside that integration.

Use the documented boundary and integration matrix to determine what the component covers in your workflow.

Read the enforcement boundary

Controls the operator supplies

Identity and authority
Authenticate principals and map them to the roles and scope the integration uses.
Trusted keys
Configure signer and verifier trust, key custody, distribution, and the supported revocation behavior.
Execution and storage
Wire the executor, configure consumption when required, and anchor retained audit state independently.
Operations
Review the deployed headers, access controls, monitoring, recovery process, and required independent assessments.

Report a suspected vulnerability

The source lists security@acgs.ai as the security contact. Include the affected component, version or commit, observed impact, and enough context for the maintainer to understand the report. Keep credentials and sensitive customer data out of the initial message.

This website does not claim a response SLA, completed penetration test, or certification.

Review the current evidence

The original security page is an engineering draft that separates local configuration from live deployment proof. The product evidence index preserves known failed and missing CI results. Stronger assurance claims need evidence for the actual release and environment.

Inspect current product evidence
SOURCE REFERENCES · 2026-09-08Source security overview Security model