Security

Designed so the agent is never the final authority.

BoundRunner treats agent output as a request—not permission. Deterministic policy, human control, credential reduction, and signed evidence remain outside the model boundary.

Security principles

Control is explicit at every boundary.

Fail closed

Identity, policy, evidence, approval, credential, and connector failures stop privileged execution by default.

Classify server-side

Connectors—not agents—own normalized operations, resources, side effects, risk, and allowed destinations.

Persist metadata, not secrets

Credential values remain ephemeral. Storage receives fingerprints, scope, provider metadata, and expiry only.

Bind every transition

Delegations and approvals bind tenant, principal, agent, deployment, action hash, resource, environment, policy, expiry, and nonce.

Verified today

Claims backed by executable tests.

The repository exercises authorization, replay resistance, tenant isolation, OIDC validation, connector boundaries, redaction, evidence tampering, PostgreSQL transactions, Helm, kind, and browser login.

  • Authorization lifecycleAllow, deny, approval, constrained execution, and replay rejection
  • Evidence integritySignature, hash-chain, tampering, missing events, export, and offline verification
  • Identity boundariesIssuer, audience, asymmetric algorithm, expiry, delegation, and deployment digest
  • Deployment pathsCompose, Helm, Kubernetes validation, kind, metrics, and trace ingestion

Transparent by design

What a production engagement still has to finish.

We do not sell the reference implementation as a certification. Production work includes your identity provider and workload federation, KMS/HSM key custody, managed PostgreSQL, external evidence anchoring, provider-specific data-flow review, internal mTLS, and an isolated Terraform runner.

Same-database cross-replica execution ownership and replay controls are implemented and tested. Multi-region write coordination and automated database failover remain deployment responsibilities.

Bring your threat model

Review the boundaries before the sales call.

Schedule technical discovery