Security
Scoped access, evidenced action, and substrate isolation across the constitutional runtime and evidence control layer.
ETHRAEON operates as a constitutional runtime and evidence control layer over intelligence infrastructure. Security here is not a bolt-on control set. It is the substrate governance boundary that separates ungoverned inference from evidenced, scoped, replayable action.
Access Control
Scoped Credentials
Every credential is scoped to the minimum surface it needs. No shared root tokens. No pan-account bearers. Rotation cadence and revocation authority named per credential class.
Multi-Factor Authentication
MFA enforced on operator surfaces, admin dashboards, and any credential mint or rotation. Sovereign clicks and biometric gates preserved as irreducible acts.
Least Privilege
Runtime processes receive the narrowest capability set that satisfies their function. Broad grants are rejected in review. Widening a grant is an evidenced event.
Audit and Evidence Layer
The evidence ledger is append-only. It records every governed action, every runtime state transition, and every artifact hash under a chain root anchor. Evidence is the primary security control, not an after-the-fact log.
- Append-only receipts on the evidence chain, one receipt per governed action, hash-linked to prior state.
- Artifact SHA-256 capture on every published asset, worker deployment, and evidence file.
- Merkle-verified periodic anchoring across major cycles, verifier reruns on every governance CI pass.
- Structured redaction rules for private and personal content prior to publication.
Secret Management
Environment Isolation
Production, staging, and local secrets are strictly partitioned. No cross-environment reuse. Environment variables are the only injection surface; no secrets embedded in source or committed artifacts.
Rotation and Revocation
Rotation is a scheduled operational discipline, not an incident response. Revocation on credential compromise is one action, not a workflow. Both are evidenced under the same append-only ledger.
Sovereign Vault
Long-lived operator credentials live in a biometric-gated sovereign vault. Extraction of a credential is an evidenced act with a per-item scope.
Deployment Review
Every deployment path enforces a governance boundary. Nothing reaches a public surface without passing content-safety, compliance, and evidence-capture gates. Deployments are reversible by construction: previous versions remain retrievable, and rollbacks are one action.
- Governance CI gates: forbidden-phrase scans, patent-count consistency (Ruling 1: 16 U.S. provisional filings, 73 specifications, 9 families), stale-data detection, evidence-chain health.
- Preview and production separation. Preview URLs are non-canonical and time-limited.
- Signed and hash-anchored artifacts for downloadable materials.
- Deploy verify: post-deploy live-body checks, not preview URL assumptions.
Substrate and Runtime Isolation
Private Boundary
Private substrate surfaces (Praxis, sovereign runtime, evidence archives) are isolated from public estate. Boundary crossings are governed and evidenced. Public deployments cannot read private state.
Edge Enforcement
Edge workers enforce content and access boundaries before origin. Rate limits, header enforcement, and route-level authentication live at the edge, closest to the caller.
AI Substrate Boundary
Model calls are wrapped by the governance layer. Prompt-injection attempts and tool-abuse patterns are detected and refused at the wrapper, not the model.
Incident Response
Incident response is a defined operational discipline. Classification, containment, evidence capture, remediation, and post-incident review are all evidenced under the same append-only ledger.
- Immediate containment: credential revocation, deploy freeze, edge rule tightening.
- Evidence preservation: no in-place mutation of affected artifacts, hash-anchored snapshots.
- Root cause: reproduction on isolated substrate before remediation is drafted.
- Post-incident receipt written to the evidence ledger, with named failed tests and remediation actions.
Report a suspected security issue via contact.ethraeon.ai (topic: security). Responsible disclosure appreciated; safe-harbor for good-faith research.
Compliance Mapping
SOC 2
Self-certified against SOC 2 Trust Services Criteria. No third-party audit claim. Public posture updated as external attestation completes.
ISO 42001
Readiness-mapped against the AI Management System standard. Governance boundary, evidence ledger, and substrate isolation align to the standard's control families.
Schedule A+
Enhanced IP Firewall applied across all published materials, patent-count consistency enforced at governance CI, ORCID-anchored provenance.
Learn More
Compliance surface for the readiness-mapped standards inventory. SLA for the operational commitments. Trust center for the public governance stance. Papers for the architectural rationale.