Security
Security at Invarra
How Phalanx keeps proposing, authorizing and executing an action separate, what stays your responsibility, and how to report a vulnerability in Phalanx or an Invarra website.
Security properties of Phalanx
The design assumes the agent may be wrong or manipulated. It limits what a wrong proposal can do rather than trying to detect every one.
| Property | What it means |
|---|---|
| Authority from authentication | Task scope comes from your application's signed assertion of the user, session and resource, never from model output. |
| Separated roles | Agent, application, operator, connector and release-signing credentials are distinct. Agent credentials can only propose. |
| Signed authorization | Contracts, activations, authority objects and receipt references are signed. |
| One-use permits | Each permit covers one exact operation, and the connector revalidates it at execution time. |
| Credential isolation | Business credentials sit with protected connectors on fixed routes, with declared destinations, bounded inputs and results, and DNS and redirect restrictions. |
| Authenticated connections | Remote connections validate TLS hostnames and certificates; signed requests carry replay protection. |
| Durable state | Tasks, budgets, permits, HOLDs and operations survive restarts. |
| Fails closed | Untrusted identity, stale or invalid state, configuration drift and resource exhaustion stop protected actions. |
| Verified supply chain | Signed artifacts, digest-pinned images and a software bill of materials. |
| Encrypted backups | Full-state backups use X25519, HKDF-SHA256 and AES-256-GCM, encrypted to a key only you hold. |
What you secure
Phalanx protects an action when its credential and execution route sit behind the gateway and every equivalent route has been closed.
The trust boundary includes your host, your identity system, the signed policy, the authoritative state sources, the protected connector and backend, and durable storage. You operate those components, and you must isolate any other credential able to perform the same action.
Report a security issue
If you find a potential vulnerability in Phalanx or an Invarra website, send us a high-level description: what is affected, what you believe could happen, whether it is repeatable, and how to reach you.
Please keep credentials, private customer data and exploit payloads out of the first message. We'll arrange a suitable channel for the details.
Use the demonstration within its displayed rules.
The public demonstration is a guided product environment. Use the interactions it explicitly provides and follow its displayed instructions. It does not authorize infrastructure probing, service disruption, access to other users' data, or testing of unrelated systems.
If you encounter unexpected data exposure or a platform vulnerability, stop the interaction and report it privately.