Tech

bernato security

Akshay Sarode
Current boundary

bernato is a foreground CLI candidate under qualification. No public binary, supported platform, qualified provider, plan, checkout, credit, or paid pilot is available.

Implemented command surface

The current source implements doctor, providers, evidence verify, and --version. These inspect readiness or verify an existing archive. They do not launch a provider, create a score, supervise a process, mutate a worktree, or generate evidence.

No public control authority

Phase 1 has no daemon, listener, browser-to-local control channel, machine pairing route, terminal, service, reverse tunnel, relay, LAN port, or generic proxy. The website is a read-only qualification surface.

Provider boundary

Provider discovery is read only. Every provider remains disabled, unqualified, and unavailable. You install and authenticate provider CLIs yourself; bernato does not collect their credentials or change their approval policy.

Platform boundary

macOS, Windows, and Linux remain unsupported until each exact native journey and artifact passes its required tests. Internal foundations are not shipped capabilities.

Evidence boundary

bernato evidence verify performs bounded offline verification of an existing bundle. Without an independently pinned key, a valid bundle proves local self-consistency only, not authorship, remote attestation, or a trusted timestamp.

Report a vulnerability

Send a minimal reproduction and impact assessment to security@bernato.dev. Do not include live credentials, personal data, or destructive proof.