OMP Session Gateway

Security

Private by design, fail-closed by default

OMP collaboration links are bearer capabilities. The gateway treats both View and Control links as secrets, and the invariants below block a release when they regress.

Out of scope in v1: mutually untrusted local accounts on a shared shell host, Portal Tunnel, and self-hosted or proxied relays. Every release runs distinctive-synthetic-secret leak scans across logs, storage, caches, URLs, and CI artifacts before it is qualified.

The full threat model, boundaries, and acceptance gates: docs/SECURITY.md · report a vulnerability privately via the security policy.

Invariants as qualified for stable v0.3.0 on 2026-09-09.