SECURITY ยท CURRENT LIMITS

Run alienctl in a local or customer-controlled environment.

The normal API listens only on the local computer. It does not include general login for a shared network. The installed customer profile adds controls for one use case. It is not a general enterprise service.

Credential and network rules

Reference data inventory

Fields required by the demonstrated effect
DataPurposeStoredPublic proof
Mission/Mandate references and stateauthority reconstructionyessynthetic references only
Actor and identity bindingattribution and verificationbounded evidencesynthetic metadata only
Policy ID and immutable versiondecision reconstructionyessynthetic value
Repository, SHA, context, state, descriptionexact effectyeslive sandbox scope
Request hash, correlation and idempotency IDsfencing and reconstructionyessafe synthetic values
Bounded provider classification/status ID/result hashresult and reconciliationyeslive bounded evidence
Credential, raw response body, raw prompts/sourcenot receipt datanonever

What alienctl handles

Handled

  • wrong authority, identity, tenant, policy, or action scope
  • duplicate or changed requests
  • cancellation before the action starts
  • provider failure, timeout, unclear reply, or failure to save a result
  • restart without sending the action again
  • redirects, large replies, unsafe local addresses, and tokens in evidence

Not proven

  • security of a compromised computer, provider, or identity system
  • prevention of every bypass
  • cryptographic proof that a record cannot change
  • code correctness, production safety, compliance, or customer readiness
  • login for a shared network or isolation for a hosted service

Report a security problem

Email hello@alienctl.com. Above Sea Level AB monitors this address for security reports. We aim to confirm receipt within three business days. This is not a promise to fix the problem within three days.

Name the affected part or version. Explain the impact. Give the smallest safe way to reproduce the problem. Do not send credentials, tokens, customer data, or private source. Do not test production or the public test repository without written approval. Give us reasonable time to investigate before you publish the report.