Deny on ambiguity
Unknown resource identity, invalid schema, stale approval, unsupported containment, or uncertain policy state stops or safely pauses the action.
Natural language can propose work. It cannot grant scope, mint approval, read secret values, or bypass the execution boundary. This page states the invariants the implementation is being built and tested against.
FLOW: model proposes → context is labeled and minimized → policy decides → approval binds the exact action → the executor enforces constraints → every outcome becomes evidence.
Unknown resource identity, invalid schema, stale approval, unsupported containment, or uncertain policy state stops or safely pauses the action.
Approvals bind actor, case, normalized action, resolved scope, risk, policy version, time, and executor audience. What you approve is exactly what may run.
The model receives handles and metadata. A broker injects secret values at the last responsible boundary, outside argv and ordinary logs.
A tool's success string is not enough. Receipts, artifacts, cleanup, and audit commit determine success, failure, cancellation, or unknown.
02 / DATA AND PROVIDERS
Riposte runs on your machine and works against your terminal. Model inference is the one place data can leave: which provider, which endpoint, and which data classes are part of explicit configuration, not silent defaults.
Exact provider support and tested data-handling profiles will be published with the first release. Until then no compatibility claims are made.
riposte.no itself uses no third-party analytics, no cookies, and no tracking scripts. See the privacy note.
03 / LIMITS
Candor is part of the security posture. As of today, the honest list of limitations is simple:
When the product ships, claims on this site will be labeled by proof class: design intent, implemented, tested, evaluated, or independently assessed.