Security and authority · Universal Apex Protected L-9.0 · 2026-07-23
Security and Responsible Disclosure
No production-security certification or universal safe harbour. This release is a static browser-local reference application, not a custody system, critical-infrastructure control plane, production smart-contract deployment, bug bounty or assurance engagement.
Deployment responsibility
A deployer is responsible for threat modelling, code and dependency review, identity, least privilege, secrets and key governance, network and tool allowlists, logging, monitoring, incident response, backup, recovery, privacy, penetration testing, supply-chain security, secure updates and professional testing.
Agentic controls
- unique identities and short-lived credentials;
- deny-by-default tool, network, file, communication and spending permissions;
- human step-up approval for external or irreversible action;
- tamper-evident telemetry independent of the agent;
- detection of credential scanning, secret reconstruction, sandbox escape, obfuscation and policy evasion;
- automatic revocation, containment, replay and recovery.
Responsible disclosure
Use the private contact identified by the operator. Include affected version, component, reproduction steps, impact and suggested mitigation. Do not access third-party data, move assets, disrupt service or disclose exploit-sensitive detail beyond what is necessary. This request does not create immunity, employment, reward or a duty to investigate or compensate.