Platform

Four boundaries, one environment.

Memory that survives the engagement, evidence you can trace, scope the system enforces, and assistants that reason without acting. Each is a property of the platform, not a promise in a statement of work.

Organizational memory

Knowledge that outlives the engagement.

Security knowledge is perishable: it lives in one researcher’s head, in a scratch file, in a chat thread — and then that person moves on. Everything here is retained and searchable instead.

Retained by default

Every engagement, observation and decision is kept and searchable. Institutional knowledge stops walking out the door.

Linked as a graph

Hosts, services, findings and evidence are connected, so the research companion has something it can actually reason over.

Versioned, not overwritten

Documents keep their history — 40+ retained versions apiece — so you can see what a finding said before it changed.

Evidence & provenance

A conclusion you cannot trace is not a conclusion.

Artefacts are hashed on capture and chained. Observation, hypothesis and conclusion stay separate labels — nothing is presented as verified until it is.

Hashed and chained

Each artefact is hashed when captured and linked into a chain, so tampering is detectable rather than deniable.

Never fabricated

Assistants may not invent an artefact. Missing evidence is reported as missing, not filled in.

Traceable reports

Every conclusion in a report resolves back to the evidence behind it, in one step.

Audit log — illustrativechain intact
evidence:addresponse-headers.txtverified
evidence:addarchitecture-notes.mdverified
scope:checkpayments.example.comdenied
agent:runresearch-companionallowed
evidence:addresponse-headers.txtverified
evidence:addarchitecture-notes.mdverified
scope:checkpayments.example.comdenied
agent:runresearch-companionallowed
Authorization model

Scope the system enforces.

Targets in or out of scope are checked on every action and the verdict is written to the audit log. It is a boundary the platform enforces, not a policy the operator remembers.

Checked every action

Each engagement defines target, scope, rules, restrictions, time window and required approvals. Every action is tested against them.

Allowed or denied, logged

The result of each check is recorded either way. A denial is evidence that the boundary held.

One audited egress

Tools and model calls leave through a single gateway, so there is one place to watch and one log to read.

Bounded AI

Assistants that reason, never act.

The companion can describe, question and recommend over authorized context. Consequential steps wait for a human — enforced by the platform rather than by prompt instructions.

Read-only by construction

Assistants observe and reason. They hold no capability to change a target system.

Human approval, enforced

Anything consequential stops and waits for an explicit human decision. The wait is a mechanism, not a convention.

Authorized context only

Reasoning is scoped to what the engagement authorizes — never the whole estate because it happened to be reachable.

Quote
Authorization and human approval are enforced security boundaries — not stated intentions.
VULZEROOperating principle

See it against your own scope.

Bring one engagement and a real scope. We will show you the environment reasoning over authorized context — and refusing everything outside it.

Platform · VULZERO