Ujex security model

Trust boundary

Agent calls are scoped by device keys, Cloud Function authorization checks, session IDs, and audit logging. Risky tool calls and outbound sends can require human approval before external work runs.

Secrets

Tool credentials are stored encrypted and injected server-side during invocation. Agent-side credential reads are denied.

Prompt-injection posture

Inbound content is scored as a risk signal. Attachments mark a session untrusted unless scanned clean. Ujex does not claim to catch every injection.

Evidence

Privileged activity is written to a hash-chained ledger and can be exported with a signed manifest for offline verification.

Not covered by this launch

External penetration test results, external ledger anchoring, and legal compliance certification are not included in the launch claim.