Security · Execution boundary

Policy first. Credentials isolated. Supported outcomes evidenced.

Pakkawork uses provider-agnostic control-plane architecture, with Google Workspace as the first provider family. Supported contracts enter the execution path; the model proposes an action and deterministic controls decide whether it may run.

Before

Policy decision

No call runs first

2

Critical approvers

Distinct humans

Signed

Evidence ledger

Append-only

Execution route / PW-01

Proposed call → evidenced outcome

Gated
  1. 01Pin contract and hash
  2. 02Score shape and arguments
  3. 03Collect required approval
  4. 04Execute with tenant token
  5. 05Append result; check if defined
MCP and REST enter the same gate. Changing transport, framework, model, or wording does not create a second execution path.

Execution controls

Six boundaries around every governed call.

Identity, OAuth, secrets, egress, policy, and evidence are enforced by separate server-side controls instead of relying on an agent prompt.

  1. 01 / Identity

    Browser and agent identities stay separate

    Browser sessions use Supabase Auth. Agent API keys are shown once, stored as sha256 hashes only, and cannot be recovered from their database representation.

    Hash-only keys
  2. 02 / OAuth

    Each tenant owns its OAuth boundary

    Connections use per-tenant OAuth apps and minimal scopes. PKCE protects the handshake, while single-use OAuth state is consumed atomically so it cannot be replayed.

    Atomic state
  3. 03 / Secrets

    Provider tokens remain server-side

    Tokens use AES-256-GCM envelope encryption with a data key wrapped by a key-encryption key. Tokens are never returned to the browser or exposed through MCP.

    AES-256-GCM
  4. 04 / Egress

    Supported outbound routes are contained

    Supported execution uses a strict host allowlist. Redirects are handled manually, credentials are stripped across origins, and the contract hash is re-checked immediately before execution.

    Contained route
  5. 05 / Gate

    Policy decides before execution

    Risk is computed from the API shape and actual arguments. The required approval threshold is pinned to the request, and critical actions need 2 distinct approvers.

    Pinned decision
  6. 06 / Evidence

    Outcomes enter durable evidence

    The ledger is append-only and signed. Limited Use redaction keeps content out of retained evidence, while durable jobs and atomic RPC transitions prevent half-applied control states.

    Signed ledger

Security boundaries

State the control—and its limit.

01

Tenant isolation

Row-level security covers all tenant tables. Narrow server repositories handle privileged access, and tenant-scoped writes cannot be read, changed, or interleaved by another workspace.

02

Verification boundary

22 live contracts verify results with real API read-back. The other 533 published contracts are generated and unchecked, so Pakkawork does not present them as verified.

03

Evidence, not certification

Pakkawork records control decisions and signed evidence. Those records support a governance review; they do not certify an organization or replace its own assurance process.

Read the full Privacy Policy and Terms of Service. Questions about architecture, controls, or a security review can be sent to admin@pakkawork.com.