Architecture

Threat model (summary)

This public summary describes the risks ZeroGrant addresses without publishing the internal security construction. It is not a penetration-test report.

  • Protected assets: owner authority, sensitive source data, and bounded results.
  • Threats considered: stolen credentials, malicious integrations, restored system state, and insider misuse.
  • Security objective: deny use outside live owner authority and return only the approved output.
  • Out of scope claim: ZeroGrant is not a GDPR processing safe harbour.

Detailed threat models and control evidence are available during controlled security review.