Serious AI needs clear control boundaries.

Security is not a badge or a paragraph in a privacy policy. It is the disciplined separation of identity, data, providers, billing, evaluation, orchestration, and release authority—paired with honest disclosure about what remains outside the guarantee boundary.

Controls should fail closed without becoming a black box.

The public posture is intentionally specific about responsibilities and limits while withholding operational detail that would make the system easier to attack.

01

Separate authorities

Identity, billing, orchestration, evaluation, provider transport, and CRE release have distinct responsibilities. No convenience layer silently inherits another layer’s authority.

02

Minimum necessary data

Product features receive the bounded context they need. Secrets, raw credentials, and private rejected material do not belong in ordinary browser storage or public responses.

03

Server-owned trust

Authenticated sessions, entitlements, protected mutations, provider credentials, and final release evidence remain server owned. Browser labels cannot promote authority.

04

Replay without reuse

Audit history can explain a decision path. It cannot mint a new release, turn prior context into truth, or replace fresh adjudication.

Know what crosses a boundary and why.

Provider-backed features necessarily process selected material outside the Coherence application boundary. Coherence surfaces that posture during account setup and keeps product-improvement use separately controlled.

You choose the work

A prompt, upload, dictation clip, source, or explicit decision begins the product workflow.

Coherence scopes context

Only applicable history, project context, anchors, and repair constraints should enter the active turn.

Providers process a task

Managed AI, search, transcription, identity, billing, email, storage, and infrastructure services receive material when their feature is used.

CRE governs the answer

Provider output remains candidate material. CRE—not the provider—controls assertion release.

Records preserve continuity

Plan-scoped chat, reliability, repair, usage, audit, and operational records support the product and user review.

You retain data rights

Coherence provides account, export, privacy, subscription, and deletion paths subject to disclosed retention and provider obligations.

Inspect the posture by control domain.

These summaries are public-safe. They describe the intended control outcome without publishing credentials, vendor topology, exact defensive thresholds, or unresolved attack detail.

C-01Identity and sessions

Managed identity, server-owned sessions, and protected account actions.

Coherence uses managed identity paths and server-owned session controls. Sensitive account changes require current identity state and, where applicable, recent reauthentication or multi-factor verification.

  • Passwords, password hashes, provider tokens, and MFA secrets are not stored by the browser application.
  • Unavailable social or enterprise sign-in methods are not presented as working controls.
  • Session revocation and account actions remain separate from CRE.
C-02Privacy and provider processing

Explicit processing notice, bounded context, and separate improvement choices.

Account activation explains that selected prompts, uploads, retrieved context, candidate answers, and repair context may be processed by managed services when those features are used.

  • Product-improvement use is controlled separately from service operation.
  • Recalled context remains candidate material, not a truth store.
  • Privacy settings can pause provider-backed features without weakening the release boundary.
C-03Secrets and least privilege

Credentials stay outside source and browser-visible configuration.

Provider, billing, identity, signing, and infrastructure credentials are resolved through protected runtime boundaries. Deployment and operational identities are designed around scoped roles rather than shared application authority.

  • Secrets are not product content and never become reliability evidence.
  • Presence of a credential does not authorize a provider route or release.
  • Operational access and irreversible actions remain separately controlled.
C-04Subscriptions and purchases

Verified billing events change access, never truth.

Web and App Store purchase paths use their respective protected billing systems. Plan and entitlement changes follow verified provider events and remain isolated from CRE adjudication.

  • Coherence does not collect raw card details.
  • Restore, renewal, cancellation, and management routes follow the active billing provider.
  • Plan tier can change capacity, never assertion validity.
C-05Application and release integrity

Bounded browser projection and reviewable build posture.

Public product responses are reduced to reviewed fields, while private operational and candidate material stays outside the ordinary browser projection. Native packaging and software supply-chain checks remain separate from runtime answer authority.

  • Unreleased candidate text cannot become final through a UI label.
  • Health, deployment, or scan status does not prove answer correctness.
  • Release actions remain explicit human decisions.
C-06Audit, telemetry, and evaluation

Observe the system without creating a second runtime judge.

Product telemetry, economic records, audit history, and internal evaluation support operations and improvement. They are evidence planes, not CRE inputs or release controls.

  • Product and internal evaluation records remain separated.
  • Cost, score, or test metadata cannot authorize a response.
  • Purpose-limited records preserve privacy and authority boundaries.
C-07Data export and deletion

User-facing lifecycle paths with disclosed provider and retention limits.

Coherence exposes in-product data inventory, export, subscription management, and account deletion paths. Some billing, legal, tax, fraud, or provider records may remain subject to independent retention duties.

  • Deletion revokes product access before asynchronous cleanup completes.
  • App Store subscriptions remain managed through Apple.
  • Public deletion status does not expose a principal identifier.

What a signal cannot prove.

Clear negative boundaries are a security control. They prevent a plausible operational signal from being promoted into an authority it was never designed to hold.

Provider output

Not released truth

Fluency, citations, search results, or model agreement remain candidate material until CRE adjudicates the answer.

Authentication

Not epistemic authority

A valid user or session can access features. Identity does not make a claim correct or a source authoritative.

Billing status

Not reliability status

A paid plan unlocks capacity and features. It cannot approve text, repair a defect, or change the release standard.

Audit evidence

Not runtime control

History can support review and replay. It does not silently re-enter the current decision or release a candidate.

Report a security concern privately.

Please do not publish sensitive details, customer data, credentials, or exploit instructions. Send a concise description, affected surface, reproduction prerequisites, and impact to support@invaris-ai.com with the subject “Security report.” We will route it for review.

No online service is perfectly secure. Coherence does not claim certification or control assurance that has not been independently completed and explicitly published.