Skip to main content

Security

Security starts with who holds the keys.

The hosted control plane manages non-secret authority material. Enforcement, credential resolution, provider contact, and the gateway ledger remain inside customer infrastructure.

Customer credential boundary

The provider credential stays with the customer.

  • Hosted RANKIGI never receives or resolves the governed provider credential
  • The customer-run gateway resolves credentials through customer-controlled infrastructure
  • The agent and optional stdio bridge do not receive the provider credential

Enforcement

Unknown authority fails closed.

  • The gateway authenticates the workload and run
  • Signed grants are intersected with loaded policy
  • Authority is reserved durably before provider dispatch
  • Required deny or unknown decisions stop before provider contact

Evidence

Claims follow recorded evidence.

  • Provider-contact claims require gateway attempt records
  • Ambiguous provider outcomes remain indeterminate until reconciled
  • Receipts are append-only and bind immutable preimages
  • Authority Packets are interpretable by the offline verifier

Disclosure

Security reports go straight to review.

  • Report suspected vulnerabilities to security@rankigi.com
  • Do not include provider secrets, private keys, or customer evidence in initial email
  • Coordinated disclosure is requested

Current status

RANKIGI does not currently claim SOC 2 certification, regulatory approval, guaranteed compliance, general availability, or high-availability support for the active design-partner pilot.

For the implemented pilot boundary and remaining acceptance work, review the pilot acceptance page.