Strict configuration
Bounded parsing rejects duplicate members, malformed encoding, non-standard numbers, and unknown fields before startup.
Security & trust
Hormuz documents what the alpha enforces today, what the deployment must own, and what still requires independent proof.
Data handling
Hormuz inspects request material transiently where policy requires it, while routine ledgers retain bounded operational evidence rather than the content itself.
Current controls
Bounded parsing rejects duplicate members, malformed encoding, non-standard numbers, and unknown fields before startup.
Remote provider endpoints require HTTPS, credential-bearing URLs are rejected, and provider redirects are never followed.
Identity, policy, budgets, privacy settings, DLP, and approvals are resolved before the governed provider call.
Short-lived sessions, atomic refresh rotation, replay-family revocation, and secure client credential custody.
Open enterprise gates
They require real customer-environment work, operational proof, or an independent party—not another marketing claim.
Security review
We will separate existing Hormuz evidence, customer-owned controls, and genuinely open engineering work.