Trust boundary

Private by default. Explicit at every exit.

ApolloBot is designed so the safe state is a stopped state, not a silent fallback.

Control

Isolation

Short-lived, resource-limited containers. Network is off unless a protocol explicitly allows it.

Control

Least privilege

Repository selection, read-only contents by default, short-lived tokens and server-side authorization.

Control

Evidence integrity

Commit SHAs, hashes, seeds, event receipts and append-only approval records.

Control

Budget safety

Estimates before execution, alerts at 50/75/90%, safe checkpoint and stop at 100%.

Control

Data rights

Every source declares access class, license, retention and redistribution permissions.

Control

No invented badges

No SOC 2, HIPAA, FedRAMP or ISO claim until it is actually earned.

!
Launch posture

Legal documents are drafts for counsel review. External integrations remain disabled until credentials, policies and named owner approvals are configured.