Browser authority
Mission Control calls server APIs. It does not hold broker credentials or directly submit trades.
GuardState separates observation, verification, policy evaluation, authorization, and enforcement so a dashboard never overstates what the system can actually control.
Mission Control calls server APIs. It does not hold broker credentials or directly submit trades.
GuardState SDK uses signed, expiring OBSERVE envelopes with nonce, digest, identity, and replay protections.
Edge Fleet requires signed node registrations and heartbeats; reported capabilities do not grant authority.
CONFIRM and ENFORCE require a server authorization bound to workspace, intent, digest, risk, policy, and approval evidence.
Provider secrets remain server-side, encrypted at rest where persistence is configured, and excluded from frontend, logs, prompts, and reports.
Material state transitions write append-only, hash-chained records. Missing integrity configuration fails readiness.
Coverage advances only through ordered, evidence-backed milestones. Missing, stale, or uncommissioned evidence scores zero.
| Surface | State | Coverage | Reason |
|---|---|---|---|
| SDK telemetry | CORRELATED | 40/100 | 3 of 7 ordered control milestones have current evidence. |
| Gateway policy path | ENFORCE CAPABLE | 90/100 | 6 of 7 ordered control milestones have current evidence. |
| Broker execution | NOT CONNECTED | 0/100 | No verified transport is connected. |
Demonstration rows prove the scoring model, not a customer connection. A score of 100 requires current evidence for active enforcement through a commissioned boundary.
Paper mode is the default. Live activation requires independently verifiable identity, legal, MFA, encrypted credential, provider capability, market data, jurisdiction, policy, immutable history, reconciliation, controlled-test, and safe-mode gates. Missing or conflicting evidence rejects execution and creates an audit event.
Customers remain responsible for account authorization, trading decisions, provider agreements, regulatory obligations, access reviews, incident response, and validating their own deployment. GuardState reports the evidence it can verify and labels everything else unverified.
Cloud administers workspaces and policy. Edge instruments local runtimes. SDK telemetry is observation-only. Gateway or a verified Edge boundary may enforce only after all server-side gates succeed.
This public release does not claim SOC 2, ISO 27001, PCI DSS certification, regulatory approval, or third-party penetration-test attestation. Readiness endpoints report configured component evidence, not a blanket security certification.
Use the published security contact and include affected surface, reproducible steps, impact, and a safe reply channel. Never include real broker credentials, private keys, seed phrases, or customer trading data.