Know the boundary before you deploy.
This page distinguishes current product behavior, deployment options, and evidence mechanisms from roadmap commitments. Orivael does not use certification language for controls that have not been independently completed.
Separate model intelligence from production authority.
Orivael can evaluate and record an action without requiring the authority decision to come from the same model that proposed it.
Least authority
Installed agents receive explicit scope, tools, budget, and action boundaries.
Fail closed
Unresolved consequential actions can route to a named hold instead of silently executing.
Version bound
Workflow, model route, policy, and capability versions remain attributable to the run.
Verifiable
Runtime decisions emit signed evidence designed for offline integrity verification.
Choose where execution occurs.
| Area | Current position | Enterprise question to confirm |
|---|---|---|
| Model data | Orivael supports customer-selected local, dedicated, and third-party endpoints. | Which provider and retention terms apply to this route? |
| Credentials | Developer credentials may remain in local keychains; enterprise deployments use scoped references. | Where will secrets be stored and rotated? |
| Workflow artifacts | NodeXLoop supports local and git-native workflow artifacts. | Will project definitions remain local or enter a managed workspace? |
| Runtime evidence | Authority decisions can produce signed, hash-linked records. | What retention and export requirements apply? |
| Tenant model | Dedicated and customer-environment deployment patterns are available for scoping. | What isolation, region, and support requirements apply? |
A clear package for technical review.
- Architecture and data-flow overview
- Deployment and model-provider matrix
- Credential and access-control model
- Evidence integrity description
- Incident and vulnerability contact
- Subprocessor and retention worksheet
Responsible disclosure
Report a potential security issue privately to security@orivael.dev. Include the affected surface, reproduction steps, potential impact, and a safe contact method. Do not include live customer data.
Current capability is labeled separately from roadmap.
Trust comes from accurate boundaries, not from displaying the longest list of standards.
Available
Published behavior that can be demonstrated, tested, or deployed today.
Customer scoped
Controls and contractual materials confirmed for a particular deployment.
Roadmap
Planned work that should not be represented as completed certification.