Security fixes are applied to the latest published AXIOMOS release.
Do not publish suspected vulnerabilities, private keys, case evidence, prompts or runtime data publicly. Contact the creator privately with the release version, operating system, reproduction steps, expected behaviour and observed behaviour.
AXIOMOS stores runtime data outside the source tree in ~/.axiomos unless AXIOMOS_DATA_DIR is set. Treat signing keys, case files, transaction records and reports as sensitive. Never commit them to a public repository.
SIGILITH_ADAPTER, TRACEGUARD_ADAPTER, and AXIOMOS_LLM_ADAPTER import Python callables and are equivalent to local code execution. Configure them only with trusted modules.
Set AXIOMOS_REDACT_PROMPTS=1 to store only a salted SHA-256 digest and prompt length in cases, transactions, audits, and evidence.
AXIOMOS refuses to bind to non-loopback interfaces unless AXIOMOS_API_KEY is configured. TLS and an external reverse proxy remain required for non-local deployments.
AXIOMOS cryptographically protects governance evidence, measurement capsules, replay records, and governance diffs. It does not currently attest that the executing Python source matches an official release. An operator with filesystem write access may alter the installed runtime. Code-integrity guarantees require a separately signed manifest, reproducible build process, startup attestation, or a protected execution environment.
POST /v1/signals accepts event metadata only. Caller-supplied context.sigilith and context.traceguard measurements are rejected. AXIOMOS computes Sigilith server-side and records TraceGuard as not_run because an external signal has no model-response pair. Every resulting case includes measurement provenance indicating that caller-asserted measurements were not accepted.
The built-in RequestClassifier is a deterministic reference implementation based on transparent phrase and rule matching. It is not a comprehensive semantic safety classifier and may miss paraphrases, misspellings, multilingual requests, and novel formulations. Production deployments should provide a separately validated classifier or upstream detector while preserving AXIOMOS evidence, replay, and audit controls.
AXIOMOS applies a per-client request limit and a concurrent-connection ceiling. These controls reduce accidental overload but are not a substitute for a production reverse proxy, TLS termination, distributed rate limiting, monitoring, and network access controls.