CLAWOLF AS-OS is designed around governed execution rather than unguarded automation. Public security statements distinguish product design, lab evidence, deployed controls, and customer-specific production activation.
Product security principles
- Evidence provenance: preserve where relevant evidence came from.
- Decision integrity: bind decision context and applicable controls.
- Least authority: production actions require authorized credentials and eligible targets.
- Human oversight: require approval where customer policy or action impact demands it.
- Fail-closed behavior: block or abstain when required authority, evidence, readiness, or verification is absent.
- Two-phase commit: separate preparation from commitment for supported high-impact actions.
- Rollback readiness: evaluate and preserve rollback information where supported.
- Execution truth: distinguish intent, attempted dispatch, accepted dispatch, and verified outcome.
- Tenant scoping: bind operational artifacts and authorization to the applicable tenant context.
- Evidence continuity: preserve decision, control, action, and verification records.
Production activation boundary
Production activation is customer- and tenant-specific. Production-impacting operation is established through the applicable executor wiring, authorized credential or secret references, durable evidence services, approval policy, verifiers, rollback capability, dry-run or canary controls, and go-live authorization.
Assurance publication
Certification, audit, penetration-testing, encryption, MFA, availability, and data-residency statements appear on public pages only when current evidence supports the exact statement and scope.
Vulnerability reporting
Security reports should be sent to [email protected]. See the Vulnerability Disclosure Policy for scope and safe-harbor terms.