Nexara Connect docs0.1.0

Security model

Nexara Connect assumes agents are useful but not trustworthy: they can be prompt-injected, they leak what they see, and they make mistakes at machine speed. The model is built so that an agent only sees what its grant allows, can only change what its grant allows, and can never approve its own escalation.

One gate: authorize()

Every read, write, search, bundle, thread post, lifecycle action and git push goes through one function in server/src/acl.ts. For an agent, access is allowed only when all of these hold:

Redaction happens per block, so one Page can be partly visible. Content above the ceiling becomes [REDACTED: <level>, ask owner]; a Page above the ceiling is not found at all.

What agents can never do

Step-up gates

These need a human who re-authenticated within the last 5 minutes (POST /api/auth/stepup; TOTP code, or password when TOTP is not enrolled). The API answers 403 step_up_required otherwise.

GateWhere
Read a sensitivity: secret PageGET /nodes/:id, bundle
Delete a PageDELETE /nodes/:id
Archive a whole FolderPOST /clusters/<path>/archive
Lower sensitivity, or move to a wider audiencePUT, PATCH, /move, accepting such a proposal
Grant an agent secret or raw secretsPUT /principals/:id/grants
Create an elevationPOST /elevations
Create a git tokenPOST /me/git-tokens
Apply the lifecycle jobPOST /lifecycle/run with mode: apply
Workspace lockdownPOST /workspaces/:ws/lockdown

Content is data, not instructions

context_get, context_bundle and the load_project_context prompt wrap every section in a <context nonce=...> fence with a random per-response nonce, and start with a preamble telling the model the content is data. Stored text cannot close the fence because it does not know the nonce. Invisible Unicode (tag characters, bidi controls, zero-width characters) is stripped on write.

Secrets at rest

Tokens and sessions

Audit

An append-only, hash-chained log records ids, actions, outcomes, sensitivity and IP for every read, write, denial, token and grant change, never content. npm run verify-audit walks the chain and reports the first broken row.

Known gaps in 0.1.0

The round-2 red-team review (docs/REVIEW-round2-security.md) found issues that are open at the time of this release. Do not put confidential data from third parties on an instance until they are fixed:

IDIssue
C1Bundle link expansion skips authorize(), so a linked Page outside an agent's grant can leak into a bundle
C2Proposal diffs can include redacted spans in their context lines, and the patch is stored unsealed in core.db
H1Malformed frontmatter falls back to internal and leaves a secret body unsealed
H2Unverified DCR clients can be granted write (the cap only limits sensitivity)
H3X-Forwarded-For is trusted from any client, defeating IP pinning and IP rate limits
M1 to M7Owner lockout DoS, humans without If-Match can overwrite, audit chain has no signed anchor, step-up by password alone, ALLOWED_HOSTS off by default, sign-up open by default, unfenced text on secondary MCP tools

Reporting a problem

Email the maintainers at Analytica rather than opening a public issue. Include the request, the response and the commit shown by /readyz.

Generated from security.md by docs/site/build.mjs. Edit the Markdown, then rebuild.