Fail closed
Identity, policy, evidence, approval, credential, and connector failures stop privileged execution by default.
Security
BoundRunner treats agent output as a request—not permission. Deterministic policy, human control, credential reduction, and signed evidence remain outside the model boundary.
Security principles
Identity, policy, evidence, approval, credential, and connector failures stop privileged execution by default.
Connectors—not agents—own normalized operations, resources, side effects, risk, and allowed destinations.
Credential values remain ephemeral. Storage receives fingerprints, scope, provider metadata, and expiry only.
Delegations and approvals bind tenant, principal, agent, deployment, action hash, resource, environment, policy, expiry, and nonce.
Verified today
The repository exercises authorization, replay resistance, tenant isolation, OIDC validation, connector boundaries, redaction, evidence tampering, PostgreSQL transactions, Helm, kind, and browser login.
Transparent by design
We do not sell the reference implementation as a certification. Production work includes your identity provider and workload federation, KMS/HSM key custody, managed PostgreSQL, external evidence anchoring, provider-specific data-flow review, internal mTLS, and an isolated Terraform runner.
Same-database cross-replica execution ownership and replay controls are implemented and tested. Multi-region write coordination and automated database failover remain deployment responsibilities.
Bring your threat model