Security

Security is a product boundary, not a footer claim.

The ecosystem separates public demo surfaces from private execution, protects secrets, uses approval gates for sensitive actions and avoids exposing internal infrastructure details in public pages.

Security is a product boundary, not a footer claim.
Generated and reused visual assets are composed as editorial website imagery; diagrams remain readable HTML.

Public surfaces

The public website, read-only demos, investor pages and downloadable materials must not expose command execution or private operational control.

Private actions

Model execution, workflow execution, file operations, MCP tools, device control, customer data and server administration should require authentication, authorization and approval where appropriate.

Secrets and credentials

API keys, tokens, passwords, private URLs, internal IPs and customer records must not be published in public pages, repositories or downloadable materials.

Evidence and audit

Operational changes should leave logs, selected model/node metadata, timestamps, actor identity, approval state and rollback paths when feasible.

Data security

Reasonable safeguards include least privilege, access review, environment separation, backups, encryption where appropriate, endpoint hardening and incident triage.

Vulnerability contact

Security or privacy concerns may be sent to privacy@innerchispa.us. A security.txt file is included for automated discovery.