You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Establish when a confidentiality policy survives model execution, tool use and agent delegation. Track reusable contracts, enforcement and evidence across repositories. Keep model-, vendor- and cloud-specific mechanisms in explicit adapters; unsupported properties must remain visible.
Work queue
Work one bounded slice at a time. Begin with response requirements, then implement and validate before advancing that issue's status. Hardware work has separate prerequisites and is not authorized merely by this tracker.
Execution order follows dependencies: response binding and confinement can be developed in software; measured identity is required before hardware lifecycle and protected-execution claims; disclosure authorization composes with confinement. The shared harness can start synthetically, but its live milestone depends on the component gates.
Keep existing open PRs current. A merged PR is delivered history, not a branch to keep extending. Do not close a hardware or composition issue merely because a component PR merges.
Completion discipline
Every work item needs an explicit threat model and trusted base, bounded acceptance criteria, implementation/revision links, reproducible evidence, negative controls and remaining limitations. Report requirements drafted, implemented, locally tested, hosted-tested and hardware-validated as distinct states. Closing an issue requires its stated acceptance criteria, not a generic green CI result.
The parent closes only when a documented deployment satisfies the selected end-to-end claim and the independent acceptance run is reproducible. Model correctness, unrestricted side-channel resistance and retroactive revocation of disclosed plaintext are not implied.
This issue is the canonical cross-repository backlog. Child issues own their acceptance details; local notes retain execution evidence rather than a second competing task list.
Objective
Establish when a confidentiality policy survives model execution, tool use and agent delegation. Track reusable contracts, enforcement and evidence across repositories. Keep model-, vendor- and cloud-specific mechanisms in explicit adapters; unsupported properties must remain visible.
Work queue
Work one bounded slice at a time. Begin with response requirements, then implement and validate before advancing that issue's status. Hardware work has separate prerequisites and is not authorized merely by this tracker.
Execution order follows dependencies: response binding and confinement can be developed in software; measured identity is required before hardware lifecycle and protected-execution claims; disclosure authorization composes with confinement. The shared harness can start synthetically, but its live milestone depends on the component gates.
Existing work to reuse
Delivered foundation and active PRs
Keep existing open PRs current. A merged PR is delivered history, not a branch to keep extending. Do not close a hardware or composition issue merely because a component PR merges.
Completion discipline
Every work item needs an explicit threat model and trusted base, bounded acceptance criteria, implementation/revision links, reproducible evidence, negative controls and remaining limitations. Report requirements drafted, implemented, locally tested, hosted-tested and hardware-validated as distinct states. Closing an issue requires its stated acceptance criteria, not a generic green CI result.
The parent closes only when a documented deployment satisfies the selected end-to-end claim and the independent acceptance run is reproducible. Model correctness, unrestricted side-channel resistance and retroactive revocation of disclosed plaintext are not implied.
This issue is the canonical cross-repository backlog. Child issues own their acceptance details; local notes retain execution evidence rather than a second competing task list.