SECURITY
Verified controls,
boundaries, and open work.
EvoCortexAI separates controls that can be verified now from architectural requirements and work that is not yet verified.
CURRENT VERIFIED ENGINEERING CONTROLS
Evidence available today.
Private implementation repositories
Security-sensitive implementation work remains private during development and qualification.
Least-privilege CI
Website validation uses read-only permissions and immutable Action pins.
Fail-closed reviewed composition
Reviewed components require explicit composition and deterministic checks before release work advances.
Responsible disclosure
Security reports can be sent to [email protected].
REQUIRED ARCHITECTURAL BOUNDARIES
Properties the system must preserve.
Clients address Control
Apple applications must not connect directly to managed workloads or Saturn-Node.
Credentials stay scoped
Frontends must never receive workload-compute credentials.
Control stays authoritative
Saturn-Control must remain the identity, policy, desired-state, operation, and audit authority and must not run inference.
Node stays private
Saturn-Node must remain a workload-authenticated private inference service without a public client API.
PLANNED OR NOT YET VERIFIED
Controls still require qualification.
End-to-end credential readiness, complete private-transport verification, full-system security review, release-specific privacy behavior, and independent audit or certification have not yet been established.
WHAT WE DO NOT CLAIM
Security language remains specific.
✕
No unconditional guarantee that every prompt or inference stays on user hardware.
✕
No guarantee that third-party APIs are never used in future, explicitly chosen routes.
✕
No claim that Saturn-Node has been deployed as a public product.
✕
No claim of whole-system audit, certification, zero knowledge, or universal regulatory compliance.
RESPONSIBLE DISCLOSURE
Report a security issue.
Send a clear description, reproduction steps, and relevant evidence to [email protected]. EvoCortexAI does not currently offer a bug bounty programme.