Identity and access
Customer and platform administration use separate access boundaries. Organization, workspace and project permissions are evaluated before protected resources are returned.
Waltrump AI OrchestratorSecurity and customer control
WAO is designed to separate customer access, provider credentials, evidence, artifacts and optional network contribution. This page describes the public operating boundary without revealing defensive implementation details.
Customer and platform administration use separate access boundaries. Organization, workspace and project permissions are evaluated before protected resources are returned.
Certification does not enable execution. Provider requests are default-off and require an exact active project/provider/model/operation tuple, customer-managed BYOK, quota, spend, concurrency and environment gates.
Approved provider credentials are configured inside a customer project, encrypted, masked in the interface and never requested through public forms.
Customer prompts, responses, artifacts, reports and evidence stay inside the authorized organization and project boundary. Public claims use customer-safe metadata only.
Approved image, audio and video outputs remain scanner, encryption, tenant, retention and download-policy controlled. A certified tuple does not weaken artifact governance.
The reviewed agent path can propose a bounded tool call but WAO never executes it automatically. Human approval and an approved tool schema remain mandatory.
SDKs, Capture packages, private-engine materials and other artifacts remain approval and entitlement controlled. They are not public downloads.
Performance Network contribution is separate, off by default and requires authorized consent plus privacy thresholds. Raw contribution remains disabled.
Data handling follows the assigned service boundary. Sensitive-data requests receive additional review before an evaluation path is approved.
Important administrative and customer actions are recorded with customer-safe event metadata. Public growth analytics does not collect prompts, responses or credentials.
Payments, checkout, unrestricted signup, public SDK distribution, automatic provider promotion, automatic switching, Full Private WAO and Private Gateway remain disabled.
Private or custom endpoint work begins with architecture and security review. A discussion path is not an execution entitlement.
Responsible disclosure
Do not include credentials, tokens, private customer evidence or exploit material in a public message. Contact the WAO team through the reviewed support channel so the report can be handled securely.
Contact WAO