05 / TRUST BOUNDARIES

Capabilities cross explicit boundaries.

Local-first describes where the working state lives. Security depends on narrower controls at each point where code, content, credentials or network traffic gain authority.

01Code execution

The macOS execution design isolates Python and shell in a guest. A release must fail closed if that guest is unavailable.

02Files and artifacts

Privileged file access must stay within authorized workspaces. Artifact rendering requires a boundary from native application authority.

03Browser and network

Browser control is a distinct capability. User supplied destinations require validation across resolution and redirects.

04Credentials and OAuth

BYOK and OAuth are separate flows. Packaged connector authorization requires a local callback boundary and state, nonce and PKCE checks.

Read the security model