Trust Center

Trust claims should be inspectable.

ILAIOS separates engineering direction from independently verified status. This Trust Center explains what the architecture is designed to enforce, what can be stated publicly now, and what will only be published after external or operational verification.

Trust domains

Security is a system property, not a badge.

The public posture focuses on authority, access, validation, evidence, and explicit claim boundaries.

Security architecture

Authority boundaries, least-privilege tool access, backend-enforced control, validation, and evidence are part of the platform architecture direction.

Data handling

Data access is intended to remain purpose-bound, tenant-aware, and limited to the context required for authorized work.

Access control

Sensitive operations are designed around explicit identities, permissions, and approval requirements rather than implicit model authority.

Auditability

Execution state, validation outcomes, and evidence are designed to support reconstruction and review of important actions.

Responsible AI

Model output is treated as an input to governed systems, not as an unquestioned source of authorization or truth.

Vulnerability reporting

Security concerns can be reported through the verified public contact channel for triage and responsible handling.

Claim boundary

What is stated, what is verified, and what is not implied.

Publicly stated now

Architecture principles, security direction, authority boundaries, evidence-first execution, and the current public contact channel.

Verified before publication

Independent certifications, audit reports, formal compliance status, production availability, service commitments, and customer-specific controls.

Never inferred from design

A planned control or architecture principle is not represented as a completed certification, external audit, or contractual guarantee.

Common trust questions

Clear answers before stronger claims.

Can an agent authorize itself?

No. Intelligent capability and authorization are separate concerns; sensitive authority remains outside the model.

Is every action autonomous?

No. Deterministic execution, explicit approvals, and bounded tools are preferred where they provide a safer and clearer path.

Are certification claims being made?

No unverified SOC 2, ISO 27001, or equivalent certification claim is published here.

How can a security issue be reported?

Use the verified public contact channel below. A dedicated security mailbox will be published only after that address is verified as an intended public route.

Security contact

Use the verified public channel.

The only public ILAIOS mailbox verified in the current website source is contact@ilaios.com. Additional Cloudflare-routed aliases will be published by function only after their exact public purpose is verified.