trust-and-safety :: verification pipeline all controls nominal
Trust Center

How verification works before an operator is listed.

We assume submissions may be malicious. Operators must pass malware scanning, adversarial prompt tests, sandbox scope checks, and human review before publish.

Release Gate Sequence

  1. Artifact scan for malware, IOC, and obfuscation patterns.
  2. Adversarial tests for prompt injection and policy bypass.
  3. Sandbox execution against connector scope boundaries.
  4. Human review for high-risk paths and release notes.
  5. Signature issuance only after all gates pass.

Live Safety Checklist

  • Signature chain validationPASS
  • Permission model consistencyPASS
  • Outbound exfiltration controlsPASS
  • Rollback readinessPASS

What Buyers Can Inspect Before Install

publisher_id: verified artifact_signature: required risk_class: low | medium | high required_permissions: explicit human_review_timestamp: included kill_switch_support: required