Security

Bound the authority. Reduce the blast radius.

Veklom security is built around separating identity, connection, execution, evidence and recovery responsibilities instead of placing every privileged operation behind one application process.

01

Authority

Application UI and connection metadata do not mint consequence authority. CAPPO remains the execution authorization boundary.

02

Host execution

LockerPhycer is designed to keep sensitive host execution controls out of ordinary application containers.

03

Recovery

Guardian recovery actions are bounded by declared recovery authority rather than unrestricted host automation.

04

Evidence

A health response or configured integration is not promoted into cryptographic or consequence proof.

Responsible disclosure

Never disclose a secret to prove a security issue.

Do not submit private keys, access tokens, refresh tokens, installation tokens, database credentials, Cloudflare tunnel credentials, recovery signing keys or production environment dumps in public issues, screenshots, chats or pull requests.
Provide the smallest reproducible description needed to demonstrate the boundary failure. Evidence should establish the defect without expanding the compromise.
Open security.txt →
Claim discipline

Security claims stay scoped to the environment and falsifiers that actually passed.

No public page should infer certification, hardware isolation, host-compromise resistance or deployment guarantees from source code alone.