Authorize scope
Accept only an explicitly authorized repository or configured localhost/test target. Scope is not inferred or widened by the security role.
Security Factory is a verified bounded defensive factory in the ILAIOS repository. It combines authorized code, secret, supply-chain, infrastructure and local/test web-security checks with remediation, retest and independent verification boundaries.
The current verified factory is deliberately fail-closed. It does not exploit arbitrary systems, authorize external penetration testing, or imply SOC 2, ISO 27001 or other external certification.
Accept only an explicitly authorized repository or configured localhost/test target. Scope is not inferred or widened by the security role.
Run bounded defensive checks for source risk, secrets, dependency/supply-chain concerns and infrastructure configuration.
Validate supplied HTTP observations only for configured local/test targets; arbitrary external network scanning is outside this factory boundary.
Keep finding type, severity context, affected target and evidence reviewable instead of reducing security to a model-generated verdict.
Propose or execute only the bounded remediation allowed by the active workflow and permission model.
Repeat the applicable deterministic checks after remediation and keep the before/after evidence linked.
Security verification remains separate from the role that produced or remediated the finding.
Fail closed on missing authorization or unresolved gates; deliver reviewable findings and evidence when acceptance criteria pass.