Docs / Architecture Learn
Security Model
Redaction before storage, read-only serving, gated tools and trust boundaries.
Secrets and PII are never stored
Because the ledger is append-only, there is no way to delete something already committed. So this is a prevention control (RFC 0043):
- A built-in baseline redacts known secret shapes — AWS, GitHub, Slack, Google and Stripe tokens, private keys, JWTs, generic key/password assignments — from all observed content.
- Files such as
.env,*.pemandid_rsaare excluded entirely. - It runs at every raw-content entry point (the
Observerpath and the direct-read paths inrecover). [security]can only extend the baseline (extra patterns and globs), never disable it.
Read-only serving
The runtime never modifies state. Agents reach knowledge only through MCP.
Exposure
- TCP and HTTP transports should bind loopback or a trusted network and use a bearer token.
ekos_clickhouse_queryis the single scoped, audited path to a live system: off by default, one validatedSELECTonly.
Trust of stored text
Text in the ledger came from your sources and may itself contain instructions. Agents should treat retrieved evidence as data, not instructions.
Integrity
Content-addressed artifacts, checksummed segments, and per-write provenance make tampering and drift detectable.