Trust and security

Built for sensitive work from the first request.

Ghost Core protects collaboration by keeping authority explicit, secrets server-side, telemetry privacy-safe, and evidence separated from customer content.

Application boundary

Strict CSP, HSTS, same-origin isolation, no framing, and minimal browser permissions.

Abuse resistance

Rate limits, bounded request bodies, validated uploads, and fail-closed sensitive endpoints.

Secret safety

Server-only credentials, automated secret scanning, redacted errors, and no sensitive debug logs.

Supply chain

Pinned lockfiles, dependency audits, build gates, and review of high-risk updates.

Incident readiness

Privacy-safe security events, escalation ownership, containment runbooks, and post-incident verification.

Authority control

Agent and support actions are bounded by explicit leases, audit events, and revocation behavior.