Garrid Build

Security and trust

Governed by boundaries, not promises

Garrid Build treats a green demo as insufficient. Production claims are tied to scoped authority, immutable evidence, and explicit readiness gates.

Current control model

  • Tenant authorization: organization membership and role checks gate console and API access; identity alone is not authorization.
  • Frozen targets: an accepted build binds the requested repository and revision to an immutable resolved commit before execution.
  • Bounded provider spend: integer budget ceilings and provider-policy snapshots are fixed per build; the gateway reserves worst-case spend before model dispatch and terminal accounts seal against later mutation.
  • Isolated execution: hostile build work runs outside the credential-holding model gateway with deny-by-default capabilities and bounded lifetimes.
  • Human-controlled promotion: author, verifier, independent reviewer, and promotion decisions are separately evidenced.
  • Append-only evidence: lifecycle, usage, cost, recovery, and operational-proof records are written as durable receipts rather than overwritten status prose.

Availability boundary

The public site is a design-partner surface, not a claim of unrestricted general availability or a compliance certification. Repository access, model provider, budget, verifier profile, data region, and delivery controls are confirmed during qualification. Contractual SSO, certifications, regional placement, penetration-test reports, and service-level commitments are not promised unless an Order Form expressly includes and evidences them.

Data and operational practices

  • Public repository access fails closed without the required target and revision contract.
  • Private repository access requires an explicitly scoped GitHub App installation; raw repository credentials are not tenant-visible identifiers.
  • Provider, bridge, session, proof, and dispatcher secrets have distinct purposes and trust boundaries.
  • Public write paths are rate-limited, while expensive work is also constrained by organization quota and per-build budget.
  • Customer audit evidence is exportable and subject to the retention terms disclosed in the Privacy Notice and Order Form.

Responsible disclosure

Send suspected vulnerabilities to security@garrid.com with the affected URL, impact, reproduction steps, and a safe contact method. Do not access another customer's data, degrade availability, exfiltrate secrets, or run destructive tests. Garrid will acknowledge reports as operating capacity permits; no public bug-bounty payment or response-time SLA is offered by this page.

Live service signal

The unauthenticated service status endpoint proves that the public control plane is responding. It does not disclose private operational detail or, by itself, prove a customer's build path. Commercial acceptance uses authenticated receipts and the signed Guided Pilot contract.