WAO logoWaltrump AI Orchestrator

Security and customer control

Keep the evaluation boundary explicit.

WAO is designed to separate customer access, provider credentials, evidence, artifacts and optional network contribution. This page describes the public operating boundary without revealing defensive implementation details.

Identity and access

Customer and platform administration use separate access boundaries. Organization, workspace and project permissions are evaluated before protected resources are returned.

Provider execution

Certification does not enable execution. Provider requests are default-off and require an exact active project/provider/model/operation tuple, customer-managed BYOK, quota, spend, concurrency and environment gates.

Provider credentials

Approved provider credentials are configured inside a customer project, encrypted, masked in the interface and never requested through public forms.

Evidence isolation

Customer prompts, responses, artifacts, reports and evidence stay inside the authorized organization and project boundary. Public claims use customer-safe metadata only.

Generated artifacts

Approved image, audio and video outputs remain scanner, encryption, tenant, retention and download-policy controlled. A certified tuple does not weaken artifact governance.

Agent proposals

The reviewed agent path can propose a bounded tool call but WAO never executes it automatically. Human approval and an approved tool schema remain mandatory.

Controlled artifacts

SDKs, Capture packages, private-engine materials and other artifacts remain approval and entitlement controlled. They are not public downloads.

Consent

Performance Network contribution is separate, off by default and requires authorized consent plus privacy thresholds. Raw contribution remains disabled.

Retention and deletion

Data handling follows the assigned service boundary. Sensitive-data requests receive additional review before an evaluation path is approved.

Audit evidence

Important administrative and customer actions are recorded with customer-safe event metadata. Public growth analytics does not collect prompts, responses or credentials.

Disabled boundaries

Payments, checkout, unrestricted signup, public SDK distribution, automatic provider promotion, automatic switching, Full Private WAO and Private Gateway remain disabled.

Private endpoints

Private or custom endpoint work begins with architecture and security review. A discussion path is not an execution entitlement.

Responsible disclosure

Report a security concern privately.

Do not include credentials, tokens, private customer evidence or exploit material in a public message. Contact the WAO team through the reviewed support channel so the report can be handled securely.

Contact WAO