Security boundaries AI cannot decide
Priority stack
AI can never bypass the System Boundary, User Hard Deny, core Anti-Tamper, or the Recovery Boundary. The security boundary is not a negotiation with the model.
Local Core First
Core security keeps running when the API expires, the cloud is down, the model is unavailable, the network drops, or the subscription server fails. The cloud is an extension, not a security dependency.
Privacy stance
The runtime analyzes locally. Audit history stays on your machine unless you explicitly opt in to cloud analysis. The product never needs your prompts, and the Security Map is designed so it cannot be turned into a treasure map by a compromised agent.
Honest limitations
- 20131 does not claim to be complete protection, and no product is. Coverage is documented per platform and per agent — coverage beats marketing here
- Early Access ships first as a monitor: observe, alert, audit. Active blocking and rollback roll out per platform afterwards — see Roadmap
- Detection is behavioral and policy-based: it reduces risk windows; it does not promise zero incident
- Some agent integrations are observation-only today (see Supported Agents), and some OS event sources need admin mode (see Supported OS)
Foundations in design: pre-action enforcement, supply-chain and skill/MCP analysis, prompt-injection-resistant policy inputs (model output never widens its own grants), and anti-tamper. Design details are published in the security whitepaper as it matures.