Skip to content

Security model

The language model never holds financial authority.

Mandate is designed around a narrow trust boundary: models may structure user intent, while authenticated code, versioned policy, and human reviewers control every authorization outcome.

Last updated August 14, 2026

What Mandate protects

Mandate stores simulated agents, mandates, authorization requests, decisions, approval records, and audit events. The MVP does not store card numbers, bank credentials, or payment-provider secrets, and it does not execute real payments.

Authorization boundary

  • The model can translate natural-language intent into a proposed policy structure.
  • The proposal is validated against a strict schema and must be activated by a human.
  • A deterministic engine—not a model—returns APPROVED, APPROVAL_REQUIRED, or DECLINED.
  • Hard policy failures cannot be overridden by model output.
  • Scoped agent credentials cannot edit mandates or approve their own requests.

Application controls

Input and cost controls

Bounded request bodies, schema validation, model timeouts, output limits, and route-specific rate limits reduce abuse and unbounded model spend.

Tenant isolation

Organization and agent ownership are checked at server trust boundaries before financial records can be read or changed.

Database safety

Queries use parameter binding through Drizzle. Authorization requests use idempotency keys and serialized budget checks.

Decision evidence

Policy checks, risk factors, human resolutions, and linked audit events preserve why a simulated request received its result.

Prompt-injection position

Mandate treats all natural-language instructions as untrusted data. The interpretation endpoint has no payment tools, database authority, approval capability, or access to user credentials. Structured model output is revalidated before it can become a proposed mandate, and a human must activate that proposal before deterministic evaluation uses it.

Responsible disclosure

Please report suspected vulnerabilities privately through the repository's GitHub security advisory form. Do not include secrets, personal data, or exploit details in a public issue. This portfolio MVP does not currently operate a bug-bounty program.

Before broader public use

The launch plan still includes an edge WAF and bot controls, cookie-based sessions with CSRF protection, email verification, MFA, centralized observability, secret rotation, and a verified database restore drill. These are explicitly tracked rather than represented as completed controls.