Security & trust
Security claims stay bounded to implementation
EthosGate applies server-side authorization checks to workspace functions, fail-closed invariant rules, idempotency records, and one-use protected-token verification. The current implementation has meaningful limitations that remain visible.
Current scope
- No live provider credentials or provider contract tests are configured.
- Ledger linking is not claimed immutable, externally verified, or cryptographic.
- No external PostgreSQL/RLS/pgvector, object storage, queues, or production monitoring is configured.
Research provenance
Aleksandar Rodić - Founder of the Conscience by Design Initiative and Author of Machine Conscience (2025). Licensed under CC BY 4.0.
Canonical research and corpus Open the authenticated workbench