Platform

Security posture

ZeroGrant separates stored data from the live authority required to use it. Public documentation describes the guarantees and integration boundary, not the internal construction. See SDARC.

  • Authority remains owner-controlled and is limited to the approved purpose, recipient, scope, and lifetime.
  • Withdrawing authority prevents future use, and restoring an older system state does not revive it.
  • Applications receive bounded results and verification references instead of reusable source data.
  • Sandbox approval is for testing only. Production approval remains under the owner's control.

Detailed assurance material is shared under appropriate access controls during security review and diligence.