Credentials stay out of the browser
The Web UI uses a server-side gateway for upstream access so service credentials are not exposed to client-side JavaScript.
A cognition layer sits on a trust boundary.
UNBLOCK connects identities, memory, tools, permissions, and machines. Security is therefore part of the product model—not a feature added after it.
We are still hardening the system and expanding independent verification. This page describes the controls and principles in the current architecture without implying a certification or audit we have not completed.
The Web UI uses a server-side gateway for upstream access so service credentials are not exposed to client-side JavaScript.
Identities, roles, grants, and revocation define who or what may read, write, decide, and execute.
Human and agent activity remains attributable to a durable identity and organizational scope.
Privacy, audit posture, and permission requests are designed to be legible to the people affected by them.
UNBLOCK remains in private beta while its security model, operational controls, and enterprise boundaries are hardened.
We distinguish shipped controls from planned controls and do not present roadmap work as production protection.
Email virajsharma@kaeva.app with the affected surface, reproduction steps, and potential impact. We will acknowledge receipt and coordinate next steps.
View security.txt ↗