GGuardState
THE CONTROL PLANE FOR AGENTIC FINANCEGUARDSTATE CLOUD
Security & trust

Control claims require evidence.

GuardState separates observation, verification, policy evaluation, authorization, and enforcement so a dashboard never overstates what the system can actually control.

Browser authority

Mission Control calls server APIs. It does not hold broker credentials or directly submit trades.

Signed telemetry

GuardState SDK uses signed, expiring OBSERVE envelopes with nonce, digest, identity, and replay protections.

Edge identity

Edge Fleet requires signed node registrations and heartbeats; reported capabilities do not grant authority.

Gateway authorization

CONFIRM and ENFORCE require a server authorization bound to workspace, intent, digest, risk, policy, and approval evidence.

Credential model

Provider secrets remain server-side, encrypted at rest where persistence is configured, and excluded from frontend, logs, prompts, and reports.

Audit integrity

Material state transitions write append-only, hash-chained records. Missing integrity configuration fails readiness.

Verified Control Coverage · deterministic demonstration

Visibility never masquerades as enforcement

Coverage advances only through ordered, evidence-backed milestones. Missing, stale, or uncommissioned evidence scores zero.

SurfaceStateCoverageReason
SDK telemetryCORRELATED40/1003 of 7 ordered control milestones have current evidence.
Gateway policy pathENFORCE CAPABLE90/1006 of 7 ordered control milestones have current evidence.
Broker executionNOT CONNECTED0/100No verified transport is connected.

Demonstration rows prove the scoring model, not a customer connection. A score of 100 requires current evidence for active enforcement through a commissioned boundary.

Fail-closed semantics

Ambiguity is a denial, not permission.

Paper mode is the default. Live activation requires independently verifiable identity, legal, MFA, encrypted credential, provider capability, market data, jurisdiction, policy, immutable history, reconciliation, controlled-test, and safe-mode gates. Missing or conflicting evidence rejects execution and creates an audit event.

Shared responsibility

GuardState does not replace governance.

Customers remain responsible for account authorization, trading decisions, provider agreements, regulatory obligations, access reviews, incident response, and validating their own deployment. GuardState reports the evidence it can verify and labels everything else unverified.

Deployment modes

Cloud and Edge have explicit roles.

Cloud administers workspaces and policy. Edge instruments local runtimes. SDK telemetry is observation-only. Gateway or a verified Edge boundary may enforce only after all server-side gates succeed.

Assurance status

No fabricated certification.

This public release does not claim SOC 2, ISO 27001, PCI DSS certification, regulatory approval, or third-party penetration-test attestation. Readiness endpoints report configured component evidence, not a blanket security certification.

Vulnerability reporting

Report security issues privately.

Use the published security contact and include affected surface, reproducible steps, impact, and a safe reply channel. Never include real broker credentials, private keys, seed phrases, or customer trading data.

Open security.txt