# Security by explicit boundaries

> Rangoon’s security principles: configuration is not authority, connectors are not permission, and consequential actions require evidence.

Canonical: https://rangoon.ai/security/

Status: In active development. Product screenshots are design previews with illustrative data. No general availability is implied.

Security principles

## Capability is powerful. Authority is specific.

Governance belongs at the moment something consequential is about to happen.

## Configuration is not authority.

A skill describes what an agent can do. Execution authorization decides whether a specific action may proceed. Assigning a skill does not silently grant access to every system it mentions.

## Connections are not permission.

Installation, enablement, credentials, permissions, policy decisions, approval, and execution are separate boundaries. A connector must not turn broad credentials into ambient agent authority.

## Imported content remains untrusted.

Discovery should inspect files without running imported scripts. Model classifications are suggestions with evidence and review state. They are not an authorization source.

## Decisions need evidence.

The LNSAT direction separates proposed actions, policy evaluation, approvals, authorization, connector invocations, receipts, and audit evidence. Additional engines must preserve explicit execution boundaries.

## Report responsibly.

Do not publish credentials, customer data, or exploit details in a public issue. Use the repository’s private vulnerability reporting feature if enabled, or establish a maintainer-approved private channel. See SECURITY.md in the source repository.

## Scope of this website.

The public website is a static product introduction and design preview. It does not run agents, accept account credentials, provide a hosted command center, or claim security certification.

[Read the architecture](https://rangoon.ai/architecture/)



## More information

- [Documentation index](https://rangoon.ai/llms.txt)
- [AI access and policies](https://rangoon.ai/ai/)
- [Source repository](https://github.com/hypler-dev/rangoon)
