Skip to content

Security: Sigilithlabs/AXIOMOS

Security

SECURITY.md

Security Policy

Supported release

Security fixes are applied to the latest published AXIOMOS release.

Reporting a vulnerability

Do not publish suspected vulnerabilities, private keys, case evidence, prompts or runtime data publicly. Contact the creator privately with the release version, operating system, reproduction steps, expected behaviour and observed behaviour.

Sensitive runtime material

AXIOMOS stores runtime data outside the source tree in ~/.axiomos unless AXIOMOS_DATA_DIR is set. Treat signing keys, case files, transaction records and reports as sensitive. Never commit them to a public repository.

Trusted adapter configuration

SIGILITH_ADAPTER, TRACEGUARD_ADAPTER, and AXIOMOS_LLM_ADAPTER import Python callables and are equivalent to local code execution. Configure them only with trusted modules.

Prompt retention

Set AXIOMOS_REDACT_PROMPTS=1 to store only a salted SHA-256 digest and prompt length in cases, transactions, audits, and evidence.

Network binding

AXIOMOS refuses to bind to non-loopback interfaces unless AXIOMOS_API_KEY is configured. TLS and an external reverse proxy remain required for non-local deployments.

Evidence integrity versus code integrity

AXIOMOS cryptographically protects governance evidence, measurement capsules, replay records, and governance diffs. It does not currently attest that the executing Python source matches an official release. An operator with filesystem write access may alter the installed runtime. Code-integrity guarantees require a separately signed manifest, reproducible build process, startup attestation, or a protected execution environment.

External signal trust boundary

POST /v1/signals accepts event metadata only. Caller-supplied context.sigilith and context.traceguard measurements are rejected. AXIOMOS computes Sigilith server-side and records TraceGuard as not_run because an external signal has no model-response pair. Every resulting case includes measurement provenance indicating that caller-asserted measurements were not accepted.

Classifier capability boundary

The built-in RequestClassifier is a deterministic reference implementation based on transparent phrase and rule matching. It is not a comprehensive semantic safety classifier and may miss paraphrases, misspellings, multilingual requests, and novel formulations. Production deployments should provide a separately validated classifier or upstream detector while preserving AXIOMOS evidence, replay, and audit controls.

Network exposure and resource limits

AXIOMOS applies a per-client request limit and a concurrent-connection ceiling. These controls reduce accidental overload but are not a substitute for a production reverse proxy, TLS termination, distributed rate limiting, monitoring, and network access controls.

There aren't any published security advisories