Skip to content

Roadmap: no-egress / air-gapped (accredited-enclave) support #80

Description

@sandstream

Goal: kit usable as a control in a no-egress / air-gapped enclave for regulated environments.

Shipped (this session)

→ The no-egress enclave story is now end-to-end: link triage at internal mirrors, scan against signed local DBs, verify artifact provenance offline, and keep a tamper-evident + SIEM-exportable audit trail. Nothing reaches the public internet.

Deferred (decision-gated, not built — deliberately)

  • Memory class-tagging — needs a label source (config-default / per-project / inference); building an unpopulated column is dead schema. Revisit when a labeling source is decided.
  • Regulated-edition tier: FIPS · RBAC/PIV · HSM/KMS · reproducible/vendored build · accreditation docs (NIST 800-53) · native Windows (docs: document platform support — macOS/Linux native, Windows via WSL2 #44). Different product tier.

🤖 Generated with Claude Code

https://claude.ai/code/session_015ERHw6bVUz39sAuoQZ1iyg

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions