Input and identity boundaries
Zod validates domain and transport input. Uploaded content and registry responses remain untrusted.
Security model
WhoActs treats credentials, uploaded evidence, external sources and requested actions as untrusted until the relevant control has checked them.
Zod validates domain and transport input. Uploaded content and registry responses remain untrusted.
Secrets and private signing material are server-only. Connected mode refuses known sandbox key identifiers.
Connected persistence defines tenant RLS and private tenant-prefixed evidence storage.
The verifier checks signed claim binding and current mandate state; audit events are hash-linked.
Threat to control
ES256 verification, kid/JWKS and issuer policy
Protected production keys and rotation
Deterministic action, resource, jurisdiction, amount and supplier policy
Relying-party vocabulary mapping
Exact registered mandate version checked on verification
Partner Token Status List profile and SLA
MIME and size bounds; extraction treated as untrusted
Malware scanning, quarantine and disarm
HMAC, timestamp and DNS-vetted public IP pinning
Rotation and durable delivery evidence
Previous/current SHA-256 locally tamper-evident chain
External anchoring and WORM export
Production boundary
Production reliance still requires protected key custody, connected-environment evidence, authenticated user operations, backup restore tests, alerting, dependency monitoring, penetration testing, incident ownership and an agreed provider trust model.
Security reports can be sent to rob@mrprime.com. Do not include live credentials, secrets or personal data in the first message. Robert Prime aims to acknowledge a genuine report within two UK business days; that is a response target, not a remediation SLA.
The machine-readable reporting route is published at /.well-known/security.txt.
Design-partner programme
We will map the principal, representative, action, resource, policy and relying-party decision with your legal, security and operational stakeholders.