Security

Sensitive work stays behind explicit control boundaries.

ILAIOS separates a request from permission to act. Identity, policy, approval, tool scope, validation and evidence determine whether consequential work can proceed.

Trust boundary

Clients request. The control plane decides.

Web, Desktop and other clients can submit intent, show approvals and surface results. They do not become the authority source for runtime permissions or policy.

CLIENTRequest · Approve · Observe
validated authority
CONTROL PLANEAuthorize · Constrain · Verify
Request → side effect

A request does not become an external side effect by itself.

Models, tools, providers, browsers and workers remain execution resources. The control boundary decides what they may do and validation decides what may be accepted.

Trust boundary

Capability is never treated as permission.

A request becomes an accepted side effect only after authority, constraints, validation and evidence are satisfied.

Select an element to inspect its role in the governed workflow.

Authoritative control planeAuthoritative control plane

The platform remains the authority for permissions, policy, execution admission, state and acceptance boundaries.

Before execution

Before sensitive work starts, the system resolves the controls that matter.

Identity and tenant scope, policy, required approval, allowed tools and targets, data restrictions, budget and acceptance criteria are resolved before bounded execution. Missing required authority fails closed.

RequestAuthenticated intent
AuthorizeIdentity · policy · approval
ConstrainTools · targets · data
VerifyAcceptance criteria
RecordEvidence · audit context
Security principles

The public security model is simple: authorize, constrain, verify and retain evidence.

Least privilege

Authority is explicit, narrow and revocable.

Tenant isolation

Relevant data is not enough; access still requires the correct tenant and authorization context.

Human authority

Where approval is required, it is tied to the proposed action and cannot be self-issued by an agent.

Fail closed

Missing required authority, validation or evidence stops sensitive work.

Evidence over assertion

Security-relevant outcomes are supported by inspectable evidence rather than trust in model narration.

No premature claims

Certifications and attestations are stated only when independently obtained and current.

Responsible reporting

Report suspected vulnerabilities through security@ilaios.com. Report service misuse, spam or fraud through abuse@ilaios.com.

security@ilaios.com · abuse@ilaios.com