Skip to content

[minor] Add customer security boundary summary - #28

Open
libops-agent wants to merge 1 commit into
mainfrom
security-boundary-summary
Open

[minor] Add customer security boundary summary#28
libops-agent wants to merge 1 commit into
mainfrom
security-boundary-summary

Conversation

@libops-agent

Copy link
Copy Markdown
Contributor

Audience and outcome

Adds one customer-facing security boundary for institutional decision-makers and security reviewers: identities, data movement, secret handling, external model-provider processing, dependency trust, support escalation, and evidence to request before managed production use.

Claim discipline

  • Leads with the current candidate status: no customer-facing managed capability is generally available.
  • Distinguishes released standalone Vault source/plan controls from unapplied managed-customer evidence.
  • States that Task Agent inference uses an external provider and a customer key does not make inference local.
  • Does not claim certification, SLA, legal approval, data location, or retention beyond an approved record.
  • Reconciles the dependency policy: LibOps-owned components use protected managed release refs; untrusted external dependencies remain pinned; deployments record resolved immutable identities and rollback evidence.

Verification

  • make docs-check
  • Mint 4.2.687 build/OpenAPI validation
  • link, anchor, redirect, and snippet checks
  • managed release claims contract
  • Task Agent catalog check
  • git diff --check

Required review before publication

This PR is intentionally left open for named human Security and Legal approval. Agent review is not approval of claims, obligations, or publication.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants