Security

Uncertain state receives no permission to act.

GOCODE builds a local boundary with explicit trust boundaries, integrity checks, and safe shutdown when evidence is insufficient.

Trust map

Every boundary knows what to trust.

Owner, channel, and integrity checks happen before state changes.

Interface

Receives only sanitized, typed data.

does not store secrets

Local profile

In the Unix/macOS preview, checks the owner, file mode, and loopback address.

Windows: deny until native ACL

Event journal

Verifies ordering, integrity, and cursor.

durable record

Verifiable mechanisms

Protection is built from concrete refusals.

No single item replaces a future independent security review.

Replay integrity

HMAC cursor, high-water mark, and sequence validation.

Atomic recovery

Projection and cursor are committed before delivery is acknowledged.

Unsafe launch blocked

Process launch is rejected until a certified Phase 6B profile exists.

Secret broker

Checks authorization, version, availability, and revocation.

Idempotency

Redelivery does not create duplicate state.

Provider without authority

The current deterministic provider has no network, file, or process access.

Honest boundary

This is not an operational security certification.

Phase 6B native isolation, Windows/Linux qualification, real providers, and an independent review are not yet complete.

  1. Native isolation
  2. Cross-platform qualification
  3. Independent final verdict
View roadmap

Move forward with GOCODE

Join the private preview.

This link is informational: the form is inactive and no contact data is collected.

Read development status