Architecture
Threat model (summary)
This public summary describes the risks ZeroGrant addresses without publishing the internal security construction. It is not a penetration-test report.
- Protected assets: owner authority, sensitive source data, and bounded results.
- Threats considered: stolen credentials, malicious integrations, restored system state, and insider misuse.
- Security objective: deny use outside live owner authority and return only the approved output.
- Out of scope claim: ZeroGrant is not a GDPR processing safe harbour.
Detailed threat models and control evidence are available during controlled security review.