Skip to content

Ikanos — Security Posture

What a capability contains by construction, what it does not, and what we decline outright. For the feature inventory see Features; for how the declarative form is enforced at design time see Linting.


Most vendor security pages are a list of things that are true. This one is a list of things that are true, a list of things that are not, and a list of problems we have decided are not ours to solve. The third list is the one worth reading.

The reason is structural rather than modest. A capability is a file. Its whole value is that you can read it before anything runs — which only means something if we are equally exact about where reading it stops helping. A security page that claimed complete coverage would undermine the one property the product actually sells.

No certifications, and Ikanos is in beta

Naftiko holds no SOC 2, ISO 27001, HIPAA or PCI attestation. Where those frameworks appear in our material, they describe control-set mapping and evidence collection — never certification.


What a capability contains by construction

These are properties of being declarative, not features bolted on afterwards. Each one holds because the surface is data we hold before we serve it.

Control What it gives you Why the declarative form makes it structural
Output filtering Only declared output parameters are returned to the caller. An undeclared field cannot leak, because it is never projected. Not a filter that might be misconfigured — an absence.
Credential separation The agent calls the capability; the capability calls upstream. The agent never holds the upstream credential. Two blast radii instead of one shared secret. A compromised agent has nothing to replay against the upstream API.
Flow determinism Behaviour is fixed by validated YAML. The engine cannot improvise a call the spec does not contain. The action is not probabilistic. What the capability can do is bounded by what was written down.
Pre-execution inspection The complete surface — operations reachable, fields returned, credential scope — is readable before a credential is attached. You cannot enumerate, by reading general-purpose code, the set of upstream operations a credential will ever authorize. A declared surface is the artifact that makes the question answerable at all.
Bounded blast radius Four operations exposed means four operations authorized. Established by reading the artifact, not by watching production.
Fixed tool descriptions Descriptions are text in a reviewed file, not metadata fetched from a vendor at connect time. Contains description-level tool poisoning and metadata rug pulls, because there is no connect-time fetch to poison.
Design-time linting Polychro rulesets check auth hygiene, safety and governance rules in the IDE and as a CI merge gate. Linting is only possible because an artifact exists. There is nothing to lint about a server you do not own.
Exposed-side authentication OAuth 2.1 resource server, JWT validation and introspection on the exposed surface. The exposed-side token and the consumed-side credential are different objects in different blocks — an author who wanted to forward the caller's token upstream has no field in which to express it.

Where the mechanism stops

Each control above has an edge. These are the edges, stated in the same place as the claims so you do not have to find them yourself.

The limit What it means in practice
Response content is not sanitised If a customer record's notes field carries injected instructions, that content still flows through the mapping into the model's context. Typed extraction narrows the surface — one declared field rather than the whole payload — but narrowing is not sanitising.
No per-tool authorization Scopes are declared per adapter, so a token admitted to the adapter may invoke every tool that adapter exposes. Per-agent policy belongs in front of us, at a gateway or policy decision point.
Telemetry is not an audit log OpenTelemetry traces and per-capability metrics carry timing and errors. They do not carry caller identity, an authorization decision, or a retention contract. If you need a per-tool compliance audit trail, plan to add one at your gateway.
The secret moves, it does not disappear Credential separation relocates the secret from the agent's config to the engine's binding. The binding location — Vault, a Kubernetes secret, a file — is now the thing to protect. A file:/// binding is fine for a tutorial and wrong for production.
Adding a hop can cost latency For a single passthrough call, a capability is one more network hop. The wins are on multi-call paths, cacheable reads, and anywhere a vendor MCP runtime is already an opaque hop.
It requires the task shape to be known A declared capability is a warm path. When an agent meets a genuinely novel task there is no approved capability for it, and something has to produce one. An agent may well write that draft — what changes is that the output is durable and inspected rather than disposable.

What we decline outright

Five risk classes we have decided are not ours. These are design decisions, recorded so they are not quietly revisited — and so nobody has to discover the boundary during an incident.

Risk class Why it is not ours What we owe instead
Shadow and unapproved server deployments An organizational inventory and approval problem. The engine cannot know about instances it is not part of. Emit identifiable, discoverable metadata so an inventory tool can find the servers we do run.
Runtime isolation of the server process The operator chooses the container, the sandbox and the egress policy. A process cannot isolate itself. Ship a container image with sane defaults and document the expectation plainly.
Agent-side governance and SOC visibility Belongs to the platform running the agent, upstream of any tool server. Emit events an external system can consume.
What the agent does with a result Outside the engine's reach once the response has been returned. Keep results minimal and declared — which is already true.
Certificate issuance, rotation, PKI The engine consumes material supplied through a binding. It is not a certificate authority. Consume certificates correctly and never leak key material.

The scored version

We scored a capability layer against the OWASP MCP Top 10 in public, row by row, with the partials marked as partials. The result was four strong, five partial, one indirect. No row says solved — and a vendor table that claimed otherwise would be worth less than that one. If you are evaluating us, that post is the more useful document, because it argues against itself in the places where the argument is weak.

Read the scored assessment