Trust center / architecture

Know the
boundary.

NbotaiOS makes owner scope, tenant placement, execution routes, review gates, and resulting receipts visible. Infrastructure controls still depend on the deployment you choose and operate.

  • Product modelLocal-first
  • Access modelOwner and tenant scoped
  • Execution modelCapability routed

System route

Intent enters.
Bounded work leaves.

This is the product architecture at a functional level. Exact network, identity, encryption, backup, and retention settings are deployment responsibilities and should be reviewed for each environment.

01 / IDENTITY

User and tenant context

The active user, tenant, and allowed workspace establish the initial boundary.

02 / ROUTING

Capability selection

The Orchestrator selects an appropriate work lane and verifies availability before execution.

03 / REVIEW

Approval when required

Consequential actions can pause for a visible human decision.

04 / RECEIPT

Result and evidence

Finished work can retain source references, progress, and execution evidence.

Claims and responsibilities

Specific, not inflated.

VERIFIED PRODUCT PRINCIPLES

What the product is designed to expose

Owner scope, tenant-aware workspaces, capability routing, reviewable progress, human approval surfaces, and durable work receipts.

DEPLOYMENT-DEPENDENT CONTROLS

What must be confirmed per installation

Identity provider, network segmentation, encryption configuration, key custody, backup policy, retention, monitoring, incident response, and regulatory mapping.

CERTIFICATIONS

No certification is implied here

This page does not claim SOC 2, ISO 27001, FedRAMP, HIPAA, or another third-party certification.

REPORTING

Responsible disclosure path

Security reports can be submitted through the contact route or the published security.txt instructions.

Open security.txt