Treat every boundary as untrusted.
Founder input, web sources, model output, provider events, and browser identities all cross explicit trust boundaries.
Core controls
- Identity-derived tenant authorization on every production read and write.
- Server-only provider credentials and redacted structured logs.
- Source evidence and human review for model-produced claims.
- Stable idempotency keys for messages and webhook-event deduplication.
- Signature verification over raw webhook bodies.
- Rate limits, cost ceilings, retention rules, and an emergency campaign pause.
Report privately
Do not publish exploit details or personal information in a public issue. Repository operators must configure and monitor a private vulnerability-reporting channel before launch.