Only necessary capability enters the run
Models, sources and tools are filtered before context construction.
Security and authority
LowToHi assumes models can be useful and still be wrong, manipulated or overconfident. Security begins by preventing cognition from becoming authority.
Models, sources and tools are filtered before context construction.
Browser-provided tenant, workspace or capability claims are not trusted as authority.
A tool invocation cannot silently become unrestricted filesystem, network or production access.
Versions, approvals, sources, outputs and effects remain inspectable after execution.
Unauthorized data and capability are removed before the working set exists.
Token, time, tool and operational limits constrain the execution.
Sensitive operations pause until the configured authority grants exact approval.
Operational state and evidence are designed to survive process failure and controlled restoration.
Security reports should identify the affected version, boundary and reproducible impact without exposing secrets or user data. Configure the public security contact before launch.