SECURITY + TRUST

Trust boundaries should be visible before data moves.

Dextra is designed to preserve evidence, source versions, review, human authority, execution, and change history. Those controls support a defensible workflow; they do not replace authoritative records, qualified judgment, independent assessment, or customer security review.

Say what each mechanism proves.

Customer data

The open proof and public teasers use fixed synthetic data. A pilot begins only after approved data types, access, hosting, retention, and prohibited-data rules are explicit.

AI authority

AI may retrieve, compare, organize, or draft. A qualified person reviews consequential output and retains the authority to approve, reject, or release.

Integrity

A recomputed hash can reveal modification and support reconstruction. It does not prove identity, authorship, source truth, legal authority, or compliance.

Validation

Structured JSON, XML, or OSCAL must still be tested against the applicable schema, constraints, registry, profile, and receiving system.

Certification

THONIS is not FedRAMP, a 3PAO, an authorizing official, a CPA firm, an ISO certification body, or legal counsel. Dextra does not confer compliance.

Release authority

The customer defines authorized reviewers, segregation of duties, signing or key-management requirements, and the systems allowed to execute or publish work.

Define the security boundary before connecting customer data.

Before Dextra connects to a customer environment, THONIS and the customer document the approved systems and records, identities, least-privilege roles, processing location, model use, subprocessors, retention, logging, signing requirements, incident route, deletion requirements, and acceptance tests.

Public demonstrations use synthetic records. CUI, credentials, personal data, regulated records, and sensitive evidence are used only through an explicitly approved hosting and handling path.

Keep authority explicit and dependencies replaceable.

AUTHORITATIVE SOURCESCustomer-approved recordsRead-only first · least privilege · named fields
GOVERNED WORKFLOWEvidence · criteria · review · approvalHuman authority · deterministic gates · audit history
APPROVED DESTINATIONSAction, report, or controlled releasePreview · verify · rollback · portable record

Minimize access

Authorize only the records, fields, identities, and actions required for the scoped decision. Begin read-only and add write authority only after explicit review and testing.

Separate AI from authority

Models may help retrieve, compare, classify, or draft. Deterministic controls and accountable people decide whether a consequential action or release is permitted.

Fail visibly

Incomplete evidence, unavailable controls, changed sources, and failed verification should block or reopen work instead of silently producing an apparently complete answer.

Preserve customer control

Records, exports, retention, deployment, key management, model use, integrations, and exit requirements are defined with the customer and tested for the intended environment.

Specific components and providers are selected only after security, licensing, deployment, support, and exit requirements are known. THONIS does not publish private implementation choices or imply third-party endorsement.

Selected product mechanics, not customer assurance.

It demonstratesOne complete synthetic AssuranceOps case plus current screenshot-led evidence for all four products, with human authority and material boundaries visible.
It does not demonstrateCustomer deployment, production identity, external-system integration, FedRAMP authorization, SOC 2, ISO certification, official conformance, recipient acceptance, or a digital signature.

Define the data and authority boundary first.

Then design the smallest workflow that can prove useful value without hiding security assumptions.

To report a suspected vulnerability in this website or a THONIS-controlled public asset, use the responsible-disclosure path. Do not include customer data, credentials, exploit payloads, or sensitive evidence in the first message.