EKOSdocs
Docs / Architecture Learn

Security Model

Redaction before storage, read-only serving, gated tools and trust boundaries.

Secrets and PII are never stored

Because the ledger is append-only, there is no way to delete something already committed. So this is a prevention control (RFC 0043):

  • A built-in baseline redacts known secret shapes — AWS, GitHub, Slack, Google and Stripe tokens, private keys, JWTs, generic key/password assignments — from all observed content.
  • Files such as .env, *.pem and id_rsa are excluded entirely.
  • It runs at every raw-content entry point (the Observer path and the direct-read paths in recover).
  • [security] can only extend the baseline (extra patterns and globs), never disable it.

Read-only serving

The runtime never modifies state. Agents reach knowledge only through MCP.

Exposure

  • TCP and HTTP transports should bind loopback or a trusted network and use a bearer token.
  • ekos_clickhouse_query is the single scoped, audited path to a live system: off by default, one validated SELECT only.

Trust of stored text

Text in the ledger came from your sources and may itself contain instructions. Agents should treat retrieved evidence as data, not instructions.

Integrity

Content-addressed artifacts, checksummed segments, and per-write provenance make tampering and drift detectable.