bernato security
bernato is a foreground CLI candidate under qualification. No public binary, supported platform, qualified provider, plan, checkout, credit, or paid pilot is available.
Implemented command surface
The current source implements doctor, providers, evidence verify, and --version. These inspect readiness or verify an existing archive. They do not launch a provider, create a score, supervise a process, mutate a worktree, or generate evidence.
No public control authority
Phase 1 has no daemon, listener, browser-to-local control channel, machine pairing route, terminal, service, reverse tunnel, relay, LAN port, or generic proxy. The website is a read-only qualification surface.
Provider boundary
Provider discovery is read only. Every provider remains disabled, unqualified, and unavailable. You install and authenticate provider CLIs yourself; bernato does not collect their credentials or change their approval policy.
Platform boundary
macOS, Windows, and Linux remain unsupported until each exact native journey and artifact passes its required tests. Internal foundations are not shipped capabilities.
Evidence boundary
bernato evidence verify performs bounded offline verification of an existing bundle. Without an independently pinned key, a valid bundle proves local self-consistency only, not authorship, remote attestation, or a trusted timestamp.
Report a vulnerability
Send a minimal reproduction and impact assessment to security@bernato.dev. Do not include live credentials, personal data, or destructive proof.