SECURITY ARCHITECTURE
Deny by default. Isolate before trust.
HEO treats every file, script, model, plugin, connector, document, external input, and requested permission as untrusted until its source, scope, handling path, and required authority have been reviewed and explicitly permitted.
01Deny by Default
Network, filesystem, credential, database, repository, and production access remain unavailable unless the approved work order requires them.
02Ringfenced Document Handling
External documents and files enter a controlled intake path before they can reach a trusted project workspace.
03Disposable Workspaces
Untrusted code, models, tools, documents, and experimental changes are evaluated in isolated workspaces designed to be discarded and recreated without affecting trusted environments.
04Evidence Before Promotion
HEO records the source, file hash, intake date, review result, validation evidence, and approval history required before an artifact can move from intake or experimentation into a trusted workspace.
05Production Is Not the Laboratory
Production and experimentation remain separate. Candidate changes are prepared and tested outside production, independently reviewed where required, and promoted only through an authorized control path.
06Purpose-Built Environment Profiles
Operating systems, tools, models, permissions, network access, and storage access are selected according to the purpose and risk of each HEO environment rather than applying one unrestricted environment to every task.
OPERATING RULES
External inputs cross an intake boundary before they can become trusted.
01Unknown or untrusted inputs are handled only through an approved isolated environment.
02Externally sourced files do not enter trusted or production environments until they have passed the applicable HEO intake and review process.
03HEO records source, hash, intake date, classification, and review result where applicable.
04Artifacts are promoted only after required intake and validation gates are complete.
05Production access remains denied unless explicitly required by the approved task.
06Experimental tools, models, operating systems, and plugins remain confined to approved laboratory profiles.
HEO ENVIRONMENT PROFILES
Each environment has a defined purpose and trust boundary.
HEO-OS-Lab and HEO-UI-Lab can use the HEO Workbench, an internally configured desktop and tooling environment for isolated experimentation, without making underlying third-party tools part of HEO's public product identity.
HEO-CoreStable governance, work orders, evidence records, review packages, approvals, reports, and trusted operating functions.
HEO-SandboxDisposable code, model, integration, dependency, and engineering experiments.
HEO-Document-IntakeRingfenced document inspection, extraction, safe conversion, metadata capture, hashing, and intake review.
HEO-UI-LabInterface, shell, and dashboard experimentation isolated from production.
HEO-OS-LabAlternative operating-system and platform evaluation on non-production hardware or disposable virtual environments.
TRUST MODEL
Trust is earned by evidence, not location. An artifact does not become trusted because it was downloaded by an authorized user, created by an AI model, received from a known organization, or already exists inside a client environment. Trust is established through the applicable HEO intake, validation, authorization, and promotion process.