SECURITY & GOVERNANCE

Observability becomes dangerous when it has unbounded authority.

AmrudAi is being designed around explicit trust boundaries, tenant-scoped authorization, credential protection, bounded diagnostics, auditable privileged actions and AI safety controls.

◈Trust BoundaryEvery identity, query and action is scoped
mTLSPlatform channelsRBACServer-side authZSecretsGoverned credentialsAuditAttributable actionsPolicyBounded executionIsolationTenant boundaries
TRUST BOUNDARIES

Security controls align to real data and authority paths.

Browser ↔ Core

HTTPS-only customer UI, server-side authorization and role/resource scope.

Sensor / Agent ↔ Platform

Unique service identity, enrollment control, encrypted platform-owned channels and assignment fencing.

Core ↔ Data Services

Bounded internal trust, secret protection and persistence under platform authority.

Core ↔ Integrations / AI

Credential governance, egress controls, tenant scope and deterministic tool policy.

NCM ↔ Managed Device

Privileged operations separated from monitoring and protected by stronger controls.

Tenant Boundary

Identity, query, persistence and action scope designed to enforce customer isolation beyond UI filtering.

PLATFORM IDENTITY

Short-lived enrollment. Endpoint-local private keys.

  • Single-use / short-lived enrollment authority
  • Tenant/deployment and optional site/pool/role scope
  • Local key generation and proof of possession
  • CA and SAN verification; fail closed on mismatch
  • Revocation, rotation and auditable lifecycle
  • Monotonic assignment generations so stale authority cannot regain control
Enrollment authority→Local key generation→CSR / proof→Certificate identity→Fenced assignment
AI SECURITY

External text is data — not instruction.

Logs, tickets, configurations, API content, vendor messages and retrieved documents can contain hostile instructions. The product direction treats those inputs as untrusted data.

LogsTicketsConfigsAPI data
DETERMINISTIC TOOL-USE FIREWALLallowlist · schema · tenant scope · RBAC · target bounds · approvals · audit
DiagnosticsNCMRunbooksRemediation