Trust boundary

Private by default. Explicit at every exit.

ApolloBot is designed so the safe state is a stopped state, not a silent fallback.

Control

Isolation

Short-lived, resource-limited execution. Network tools are limited to the approved research phase and provider.

Control

Least privilege

Organization-scoped identity, short-lived execution credentials, and server-side authorization.

Control

Evidence integrity

Hashes, provider receipts, verified checkpoints, and append-only approval records.

Control

Budget safety

Worst-case reservations before provider calls, alerts at 50/75/90%, and checkpoint-and-stop at 100%.

Control

Data rights

Customers must declare access, license, retention, and redistribution authority for admitted material.

Control

No invented badges

No SOC 2, HIPAA, FedRAMP or ISO claim until it is actually earned.

How the boundary holds

Nothing leaves without a named human decision.

Work is generated inside an isolated executor with least-privilege identity and hash-verified evidence. The only way out is an explicit, recorded approval.

PRIVATE BOUNDARYIsolated executionLeast-privilege identityHashed evidence + receiptsHard budget capsHUMAN APPROVALthe only exitAPPROVED EXPORTFindings you choseReproducible methodsExcludes private source
Launch posture

Legal documents are drafts for counsel review. External integrations remain disabled until credentials, policies and named owner approvals are configured.