Explicit permits
Dispatch requires a short-lived permit bound to project, target, dedupe key, scope, and budget.
Security posture
The commercial service is designed to coordinate bounded requests—not collect raw repositories, credentials, or unrestricted model access.
Dispatch requires a short-lived permit bound to project, target, dedupe key, scope, and budget.
Persistent records should store metadata, content hashes, and customer-managed payload references rather than full task bodies.
Unknown identity, target state, policy, or receipt status stops delivery instead of widening authority.
Provider credentials remain customer-controlled and must never be placed in task content or audit exports.
A send interrupted before acknowledgement stays unresolved for review. It is not silently retried.
During private preview, security reports use the confidential process documented in the open-source project SECURITY.md.