Trust
Security
Ophiolite runs inside your boundary. These are the controls it has today, what they do and how they were tested — and what is still coming.
- Available
Sign-in
Your organisation's sign-in provider, or an access key. One session policy for the browser, Python and applications, asserted by a health check that compares the provider, the running server and the declared policy.
- Available
Agents
Scoped agent keys with budgets and an expiry; every change is a plan a person approved; approval never happens over MCP.
- Available
Sandboxed runs
One container per job with no network, no registry, a read-only root and resource limits.
- Available
AI use
Permission per reader and purpose, separate from permission to read; search stays inside your boundary.
- Available
Sharing
Every read and change is checked against the same permissions, whoever calls; a sharing change names the version it read.
- Coming
Access keys and hand-over
Self-service scoped keys, project service accounts and an offboarding hand-over.
Sessions
A sign-in ends after seven days without use and after thirty days at most. The provider's access tokens last five minutes and renew silently. The numbers are one declaration in the server:
IDLE = 7 * 86400ABSOLUTE = 30 * 86400
Runner limits
Each job runs with no network and a read-only file system, within these limits:
DEFAULTS = {'memory_mb': 256, 'seconds': 60, 'cpus': 1.0, 'pids': 64network='none'
Qualification record
Available Before release, an independent agent that did not build the code attacks the whole chain — sign-in, sharing, uploads, publication, agents and exit. The last run passed 1,979 checks after 3 findings were fixed. There is no external audit yet.
Report a security problem to security@ophiolite.dev.