DELEGENTRA
DELEGENTRA / TRUST

Trust & deployment readiness

The controls present in the local prototype, the gaps still open and the conditions for customer deployment.

Local prototype · Customer cloud deployment not ready

The hosted website previews the interface. The portable workbench is local and single-user. This page records the security boundary; it does not represent a new security audit or certification.

AreaPresent in the local prototypeRequired before hosted customer use
Identity & dataSession token and loopback host checks; one userManaged identity, server-side permissions and tested customer isolation
Secrets & connectionsServer environment keys; no browser key fieldSecret rotation, redacted logs and permitted connection/egress boundaries
External actionsSeparate approval for a reviewed webhook payloadScoped credentials, destination controls and confirmed delivery semantics
Tools & add-onsNo dynamic MCP/plugin marketplaceVersion/source inventory, permission review and update controls
CostsModel-call limit; this is not a currency spend capMeasured usage and enforceable project spend limits
OperationsLocal task and stage recordsAccess-controlled monitoring, recovery, deletion and incident response

A staged path to customer use

Demonstration

Use synthetic or permitted public examples while testing the workflow.

Scoped pilot

Agree the data scope, expert review, acceptance criteria and deployment controls before using customer records.

Hosted product

Verify identity, isolation, secret handling, tool permissions, cost enforcement and recovery before opening a multi-customer service.

Project labels are not security boundaries. A model instruction does not enforce access control. No broker execution, device control, multi-tenant service or compliance certification is claimed.

Read the implementation boundaries

OWASP agent security guidance