Ghost Cloud is an approval-gated AI operator. Security is part of the product promise: least privilege, human approval on sensitive actions, verification, and tamper-evident audit logs.
- Org isolation — every record is scoped to an organization.
- Deny-by-default — send / pay / delete / submit halt for approval.
- Deterministic gates — models do not decide sensitivity or execute plans.
- No secret sprawl — credentials and PII stay out of logs, screenshots, and prompts.
- Auditability — runs append to a hash-chained log.
Email the maintainer via GitHub (@mohabbis) with a private advisory if possible. Please include reproduction steps and impact. Do not open a public issue for exploitable flaws.
We aim to acknowledge within 72 hours.
In scope: cloud/ (web, worker, core), auth, run execution, approval flow, audit.
Out of scope for new feature work: the legacy desktop app’s network surface, except critical remotely exploitable issues in published installers.