Separate authorities
Identity, billing, orchestration, evaluation, provider transport, and CRE release have distinct responsibilities. No convenience layer silently inherits another layer’s authority.
Security is not a badge or a paragraph in a privacy policy. It is the disciplined separation of identity, data, providers, billing, evaluation, orchestration, and release authority—paired with honest disclosure about what remains outside the guarantee boundary.
The public posture is intentionally specific about responsibilities and limits while withholding operational detail that would make the system easier to attack.
Identity, billing, orchestration, evaluation, provider transport, and CRE release have distinct responsibilities. No convenience layer silently inherits another layer’s authority.
Product features receive the bounded context they need. Secrets, raw credentials, and private rejected material do not belong in ordinary browser storage or public responses.
Authenticated sessions, entitlements, protected mutations, provider credentials, and final release evidence remain server owned. Browser labels cannot promote authority.
Audit history can explain a decision path. It cannot mint a new release, turn prior context into truth, or replace fresh adjudication.
Provider-backed features necessarily process selected material outside the Coherence application boundary. Coherence surfaces that posture during account setup and keeps product-improvement use separately controlled.
A prompt, upload, dictation clip, source, or explicit decision begins the product workflow.
Only applicable history, project context, anchors, and repair constraints should enter the active turn.
Managed AI, search, transcription, identity, billing, email, storage, and infrastructure services receive material when their feature is used.
Provider output remains candidate material. CRE—not the provider—controls assertion release.
Plan-scoped chat, reliability, repair, usage, audit, and operational records support the product and user review.
Coherence provides account, export, privacy, subscription, and deletion paths subject to disclosed retention and provider obligations.
These summaries are public-safe. They describe the intended control outcome without publishing credentials, vendor topology, exact defensive thresholds, or unresolved attack detail.
Managed identity, server-owned sessions, and protected account actions.
Coherence uses managed identity paths and server-owned session controls. Sensitive account changes require current identity state and, where applicable, recent reauthentication or multi-factor verification.
Explicit processing notice, bounded context, and separate improvement choices.
Account activation explains that selected prompts, uploads, retrieved context, candidate answers, and repair context may be processed by managed services when those features are used.
Credentials stay outside source and browser-visible configuration.
Provider, billing, identity, signing, and infrastructure credentials are resolved through protected runtime boundaries. Deployment and operational identities are designed around scoped roles rather than shared application authority.
Verified billing events change access, never truth.
Web and App Store purchase paths use their respective protected billing systems. Plan and entitlement changes follow verified provider events and remain isolated from CRE adjudication.
Bounded browser projection and reviewable build posture.
Public product responses are reduced to reviewed fields, while private operational and candidate material stays outside the ordinary browser projection. Native packaging and software supply-chain checks remain separate from runtime answer authority.
Observe the system without creating a second runtime judge.
Product telemetry, economic records, audit history, and internal evaluation support operations and improvement. They are evidence planes, not CRE inputs or release controls.
User-facing lifecycle paths with disclosed provider and retention limits.
Coherence exposes in-product data inventory, export, subscription management, and account deletion paths. Some billing, legal, tax, fraud, or provider records may remain subject to independent retention duties.
Clear negative boundaries are a security control. They prevent a plausible operational signal from being promoted into an authority it was never designed to hold.
Please do not publish sensitive details, customer data, credentials, or exploit instructions. Send a concise description, affected surface, reproduction prerequisites, and impact to support@invaris-ai.com with the subject “Security report.” We will route it for review.
No online service is perfectly secure. Coherence does not claim certification or control assurance that has not been independently completed and explicitly published.