Security / Trust

Local-first, exportable evidence, explainable boundaries

BeforeWire keeps raw data, secrets, and full artifacts inside the customer boundary by default. External surfaces can receive only policy-approved summaries, hashes, redaction manifests, and Action Receipts.

Policy boundary

Capabilities are granted by policy by default

Path, command, tool, egress, credential, and data-action rules can be versioned. When policy changes, old approvals do not silently continue.

Local-first

Data and secrets do not upload by default

Receipts and artifacts can stay local by default. Enterprise deployments can configure private control planes, encrypted storage, TTLs, and audit exports.

Confirmation path

High-risk actions require approval or a broker

Production credentials, external API mutations, database writes, and customer notifications can be controlled through a broker, approval route, or deny policy.

Coverage matrix

Coverage strength is explicit

files=enforced, runtime=enforced, egress=governed, db=brokered, unsupported=blocked. Unsupported surfaces are not presented as recoverable.

Security contact: To report a security issue, email [email protected].