POMERION

Security

Power has boundaries.

When software can move physical things, authorization is a safety property. These are the principles Pomerion is being built on.
Principles

How we think about authority.

01

Least authority by default

Machines and models start with no permissions. Every capability is explicitly granted.

02

Fail closed

Absence of a valid decision means no action. Network loss, expired credentials or unknown models never default to allow.

03

Hardware-rooted identity

Machine identity is designed to anchor in hardware, not in configuration files.

04

Verify state, not claims

Authority depends on attested firmware, software and model state at the time of the request.

05

Revocable everything

Credentials, model approvals and permissions are designed to be withdrawn quickly and propagate to the edge.

06

Auditable decisions

Each decision is recorded with the inputs that produced it, so it can be reconstructed later.

Honesty

No borrowed credibility.

Pomerion is early stage. We do not currently hold third-party security certifications, and we won't claim any until they are earned.

We'll publish our security architecture, threat model and audit results as the platform matures.

Responsible disclosure

Found something?

If you believe you've found a vulnerability in anything Pomerion operates, please contact us privately before public disclosure. We will acknowledge, investigate and keep you informed.

security@pomerion.com