For Security & Compliance

Your data. Your device. Your audit trail.

This is a pre-acceptance source review, not a security certification. Local Python files are inspectable; no Azure, Copilot Studio, browser, installer, or production deployment is currently shipped.

๐Ÿ”’
Data residency

Local-first. On-device by default.

  • Agents, memory, and soul files live on the user's machine.
  • The former Azure tier is retired; no cloud-residency promise is made.
  • Offline and air-gapped operation require operator verification.
  • The former Tier 2 guid namespace is historical, not a current RAPP/1 identity rule.
๐Ÿ“œ
Supply chain

Auditable, pinnable, rollback-able.

  • Every agent is plain Python code โ€” reviewable, diff-able, committable.
  • Historical release tags are evidence, not current authority.
  • RAPP/1 is pinned by exact commit and SHA-256 in RAPP1_AUTHORITY.json.
  • No installer or one-command rollback is currently offered.
๐Ÿ†”
Identity

Rides on the IdP you already trust.

  • Tier 1: GitHub identity (your corp SSO via GitHub).
  • Retired Tier 2 designs referenced Azure AD / Entra ID.
  • Retired Tier 3 designs referenced M365 identity and Power Automate.
  • No identity claim is accepted without the RAPP/1 ยง13 trust chain.
What RAPP never does

No telemetry phoning home. The brainstem doesn't call back to us. Period. You control where requests go.

What RAPP never does

No vendor-shared agent registry. Your agents live in your repo, your tree, your cloud. We don't host them centrally.

What RAPP never does

No opaque skill interpretation. Agents are code, not markdown the LLM re-reads. You can read exactly what the agent will do.

The agent is a file. The file is reviewable code. The deployment runs in your tenant, on your identity, against your data. Security review starts with git log โ€” not a spec document.