Credential boundary
Halro stores Provider Credentials; applications receive independently revocable Gateway Keys.
Restrict Admin access, protect the Master Key, and isolate data directories by environment.
SECURITY
Halro provides a local control plane around model access. It does not replace host security, network controls, key custody, backup media, or organizational process.
CONTROL / RESPONSIBILITY
Halro stores Provider Credentials; applications receive independently revocable Gateway Keys.
Restrict Admin access, protect the Master Key, and isolate data directories by environment.
Projects enforce route/model authorization, CIDR and field policy, rates, concurrency, and budgets before Provider I/O.
Configure least privilege and verify policy against the actual application boundary.
A Provider can use an Admin-managed outbound proxy; the resource chain selects the real target.
Own network egress, proxy trust, DNS, certificates, and destination allowlists.
Requests, Attempts, usage, pricing evidence, audit records, and integrity checks remain in local data.
Own backups, offline verification, restore drills, retention, and external alerting.
CURRENT BOUNDARIES
Topology: the current supported model is a standalone single-writer instance.
Initialization: installation does not create configuration, data directories, or a Master Key, and does not start the service.
Website data: this site does not require uploading prompts, responses, credentials, or local audit data.
Maturity: experimental interfaces such as Run Governance must be evaluated under their adjacent maturity label.