CURRENT PRODUCT BOUNDARY

Know exactly what crosses the boundary.

PermitGraph is a customer-run exposure diagnostic for AI agents and machine identities. The default pilot keeps raw exports in the customer environment, accepts metadata rather than credential values, and produces deterministic evidence for human review.

  • Customer-run
  • No secret values
  • No infrastructure changes

CURRENT CONTROLS

What the product does today.

These are implementation and delivery boundaries in the current scanner. They are not certifications and do not replace the customer's own security review.

01

Metadata only

PermitGraph analyzes identity, credential-record, privilege, ownership, and resource metadata. Common secret-like keys are rejected before scanning; customer review is still required.

02

Local execution

The packaged CLI reads a local JSON file and has no runtime package dependencies or telemetry path. The public worksheet calculates its graph, findings, and digest in the browser without submitting worksheet values.

03

Zero custody by default

The customer keeps raw exports inside its environment and shares only an approved screen view, findings list, or evidence package. A controlled transfer requires written terms before it begins.

04

Tamper-evident evidence

A SHA-256 digest covers the canonical normalized graph and findings. A matching digest shows the reviewed evidence has not changed; it does not prove the source export was complete or accurate.

DEFAULT DATA FLOW

Four customer-controlled steps.

The customer decides what is exported, what is scanned, and what evidence may leave its environment.

  1. 01Export

    An authorized operator selects approved identity and resource metadata.

  2. 02Review

    The customer removes disallowed fields and confirms no secret values are present.

  3. 03Scan locally

    The CLI or browser worksheet creates findings and the integrity digest.

  4. 04Share selectively

    The customer approves a screen view, findings list, or evidence package for review.

FIT-CHECK CONTACT DATA

What the request form stores.

This describes the current form implementation. It is separate from scanner input and does not replace company-specific commercial, security, or privacy terms.

  1. 01Only after submit

    A prospect record is created only after the visitor submits the form and affirmatively asks Pith Strategies to contact them.

  2. 02Exact fields

    Name, work email, company, optional role, selected system families, approximate identity range, decision window, stated workflow and decision, consent, source-page attribution, request ID, creation time, and request status.

  3. 03Limited purpose

    Pith Strategies uses the record to evaluate and respond to the requested PermitGraph fit check, suppress a repeat submission from the same email for 15 minutes, and track the request's sales stage. It is not scanner input.

  4. 04Questions or requests

    To ask about, correct, or request deletion of a submitted fit-check record, email pithstrategies@gmail.com from the submitted address or include the request ID so Pith Strategies can verify the record.

INPUT CONTRACTS

Customer-supplied metadata supported today.

These are local adapters for approved JSON exports, not hosted collectors or direct connections to customer systems.

Normalized

Agent, owner, credential alias, allowed action, and target-resource relationships.

AWS IAM

Workloads, roles, policy grants, trust relationships, and credential lifecycle metadata.

Microsoft Entra

Service principals, application permissions, delegated grants, directory roles, and credential metadata.

GitHub Actions

Workflows, repositories, environments, permission declarations, and secret-record metadata, not secret values.

MCP tool registry

Customer-approved server catalogs, agent owners, credential aliases, effective tool grants, auth posture, and customer-classified action risk.

Supabase

Edge Functions, project roles, grants, RLS state, data surfaces, and supporting identity metadata.

EXPLICIT LIMITS

What PermitGraph does not claim.

  • No hosted production collector is included in the current pilot bundle.
  • No penetration test, compliance certification, or proof of inventory completeness.
  • No infrastructure mutation, automatic remediation, or runtime authorization enforcement.
  • No raw customer export should be emailed to Pith Strategies.
  • No data transfer, production work, or payment starts before mutually signed commercial and security terms.

RESPONSIBLE REPORTING

Report a vulnerability safely.

Email pithstrategies@gmail.com with the subject [SECURITY] PermitGraph vulnerability report. The standard discovery file is available at /.well-known/security.txt.

  1. 01Use synthetic evidence

    Include the affected URL, release, CLI command, or adapter, the expected security impact, and concise reproduction steps using non-secret metadata.

  2. 02Do not email sensitive material

    Do not send passwords, tokens, private keys, client secrets, real customer exports, personal data, or destructive payloads. Request a secure coordination method first.

  3. 03Stay within authorization

    Do not disrupt availability, access or modify another person's data, create persistence, use social engineering, or test systems and data you are not authorized to use.

  4. 04Know the boundary

    This policy does not promise a bounty, response deadline, service level, or authorization beyond applicable law and access you already have.

SECURITY FAQ

Questions a buyer should ask.

For a company-specific review, Andrew will document the approved sources, operators, evidence-sharing method, and required commercial or security terms.

Does Pith Strategies receive raw exports?+

Not in the default delivery mode. The customer runs PermitGraph locally and authorizes what screen view, findings, or evidence package may be shared. Any raw-metadata transfer is an exception that requires written confidentiality, access, retention, deletion, and incident terms first.

Does PermitGraph accept secrets?+

No. The schema is metadata-only and rejects common password, token, private-key, client-secret, API-key, bearer, JWT, and connection-string field names. Automated rejection cannot identify every sensitive value, so the customer must still review each export.

Does the customer bundle call an external service?+

No. The packaged CLI performs local file reads, optional local report writes, and local SHA-256 calculation. It has no runtime package dependencies, hosted collector, or telemetry path.

What does the public worksheet send?+

The worksheet sends nothing. It builds the normalized graph, runs the scanner, and creates downloadable evidence in the browser. A separate fit-check form submits business contact details only when the user explicitly completes and submits it.

What does the integrity digest prove?+

It proves that the normalized graph and findings covered by that digest have not changed. It does not prove that the source inventory was complete, accurate, authorized, or secure.

Is PermitGraph production identity infrastructure?+

Not today. The current product is a deterministic exposure diagnostic and evidence generator. Continuous collection, tenant isolation, SSO/RBAC, formal assurance, and runtime enforcement remain future product requirements.

SAFE FIRST STEP

Test one path without transferring a file.

Use review-safe aliases in the browser-local worksheet. If the evidence is useful, request a 20-minute fit check and bring only the approved screen view, not the input JSON.

Prepare one redacted path Request a fit check