Security
Power has boundaries.
How we think about authority.
01
Least authority by default
Machines and models start with no permissions. Every capability is explicitly granted.
02
Fail closed
Absence of a valid decision means no action. Network loss, expired credentials or unknown models never default to allow.
03
Hardware-rooted identity
Machine identity is designed to anchor in hardware, not in configuration files.
04
Verify state, not claims
Authority depends on attested firmware, software and model state at the time of the request.
05
Revocable everything
Credentials, model approvals and permissions are designed to be withdrawn quickly and propagate to the edge.
06
Auditable decisions
Each decision is recorded with the inputs that produced it, so it can be reconstructed later.
Honesty
No borrowed credibility.
Pomerion is early stage. We do not currently hold third-party security certifications, and we won't claim any until they are earned.
We'll publish our security architecture, threat model and audit results as the platform matures.
Responsible disclosure
Found something?
If you believe you've found a vulnerability in anything Pomerion operates, please contact us privately before public disclosure. We will acknowledge, investigate and keep you informed.
security@pomerion.com