Skip to content
Security control plane

The security boundary stays outside the agent.

ELITZE connects identity, reachability, policy, authorized execution, runtime observation, adversarial validation and evidence without pretending missing telemetry is real.

ELITZE control plane architecture: discovery, governance, validation and evidence
Control surface

Controls at the boundary.

Evidence-gated

Identity isolation

Governed actions carry a tenant-scoped workload identity.

Policy enforcement

Sensitive actions are evaluated against explicit policy before execution.

Credential boundaries

Secrets and credentials stay outside the agent context and are brokered under controlled infrastructure.

Tool governance

Tool and protocol requests are treated as authorization decisions, not trusted instructions.

Evidence

Decision and enforcement records preserve the security path for investigation and retest.

Containment

Containment can be handed to a separately authorized executor for isolation or credential action.

ELITZE authorized security validation and pentest lifecycle
Adversarial validation

Pentest every release. Govern every agent. Verify every fix.

The repository contains an authorized pentest control surface and release-security skill definitions. A pentest result is only a result when an actual runner returns evidence; the UI deliberately reports the runner as unavailable when it is not connected.

Authorized scope required
API / MCP / agent profiles
Policy decision before execution
Finding + retest evidence
Open pentest workbench

Defensive principles

Fail closed when a security-critical dependency is unavailable.
Never treat untrusted external content as policy instructions.
Never represent an unimplemented control as active protection.
Keep internal control credentials out of browser clients.
Operational loop

Discover → Evaluate → Enforce → Record → Verify.

External intelligence and customer infrastructure supply inputs; they do not replace the ELITZE decision and evidence boundary.

identity → policy → authorization → execution → evidence → retest