Implemented controls
- Invite-only Cognito identities with authorization-code PKCE and short-lived tokens.
- Tenant partition keys for user, device and MCP lookups.
- High-entropy device and personal-agent credentials stored only as SHA-256 hashes.
- Private, versioned S3 release buckets and short-lived download URLs.
- SHA-256 release verification, safe archive extraction and Linux rollback health checks.
- MCP origin validation, protected-resource metadata, read-only scopes and immutable-style audit events.
- Encryption at rest for DynamoDB/S3 and TLS for public service paths.
Current beta limitations
Transparent preview posture
The Windows MSI is checksum-published but is not yet Authenticode-signed. MCP personal tokens are bearer credentials and require careful client secret handling. Formal compliance attestations are not claimed on this page.
Operator responsibilities
Use the shortest practical token lifetime, revoke unused credentials, restrict administrators, segment OT networks, verify device hardware/OS support, validate model behaviour for the site, and keep safety logic outside probabilistic inference paths.
Report a security issue
Email info@oddessy.io with a concise impact description and a safe reproduction. Do not include real customer credentials, personal data or production imagery.