SECURITY & PRIVACY / v0.1.0

Verification needs trustworthy foundations.

The current release candidate is a local, single-computer evaluation product for synthetic data. These protections have a specific scope.

Evidence encrypted at rest

Evidence objects use AES-256-GCM with a key derived locally from a passphrase and salt. The passphrase is not stored in PostgreSQL. Database dumps and backups are not automatically encrypted.

Authenticated local communication

The API listens only on 127.0.0.1 and requires a local bearer token. This is local access control, not enterprise authentication or authorization to expose the service to a network.

Authorized sources and integrity

File reads are confined to registered scopes. The engine checks path boundaries, object integrity and evidence access. Reads and exports are audited; missing authorization or integrity does not yield a pass.

Local runtime; explicit network scope

The v0.1 runtime includes no analytics, telemetry, crash reporting, update checks or model-provider calls. Initial dependency installation requires registry access. A test egress guard is not a production firewall; supported HTTP verification must be assessed according to its configured target.

Your computer remains part of the boundary

Protect the token, passphrase, data folder and PostgreSQL with operating-system permissions. Retention and coordinated evidence deletion are not implemented. v0.1 must use synthetic data only.

Responsible disclosure

A verified private vulnerability-reporting channel is still a publication requirement. Do not submit exploit details through public issues. This website does not present an unverified reporting channel as operational.

AI does the work. Tesven verifies.

Get Tesven ↗