Security for sovereignty
Guardrails that keep memory, agents, and data under user control.
Philosophy
The thesis
LegionForge treats security as a way to preserve self-ownership. Your memory, preferences, agent history, and tool permissions should be inspectable, portable, and governed by rules you control.
LLMs are useful collaborators, but they are not the authority boundary. Anything that changes memory, expands capability, touches sensitive data, or invokes a tool crosses deterministic checks first: rules, signatures, trust scores, hash chains, capability scopes, and human gates where the action deserves one.
Five non-negotiables
Principles that shape every component
Sovereignty first
The owner can inspect, tune, move, revise, forget, and govern the system. Control starts with the user.
Local-first custody
Core memory and audit state live on infrastructure you control. Cloud services are optional, not the root of trust.
Human authority
Irreversible changes, sensitive writes, and unresolved conflicts cross a human-controlled boundary.
Deterministic guardrails
Regex, hashes, signatures, trust scores, and capability lookups run before the model gets a vote.
Scoped privilege
Capability is tied to the active task and expires when the task ends. No persistent agent privilege by default.
Differentiators
What changes when the owner is the root of trust
| LegionForge | Cloud agent platforms (OpenAI Operator, Anthropic Computer Use, Google Mariner) |
OSS agent frameworks (LangChain, AutoGen, CrewAI) |
|
|---|---|---|---|
| Where it runs | Your hardware | Their hardware | Your hardware |
| Where your data sits | Your PostgreSQL | Their database (opaque) | Wherever you wire it |
| Tool-call security | 7-check deterministic pipeline on every call (enforced) | Their internal checks (you don't see them) | Whatever you wire (often nothing) |
| Prompt-injection detection | 29 patterns, two tiers, at trust boundary | Vendor-defined | Not bundled |
| Audit trail | SHA-256 hash-chained audit_log |
Their logs (you don't get them) | Not bundled |
| HITL on destructive actions | Enforced via approval gate | Sometimes | You wire it |
| Tool signing | Ed25519 on every registered tool | Internal | Not bundled |
| License | Open source, project-specific licenses | Proprietary | MIT / Apache 2.0 |
What we defend against
Threat model
INJECTION_DETECTED.rm -rf /, DROP TABLE, fork bombs, pipe-to-shell, metadata endpoints.What we don't claim to catch
Honest limits
- A malicious human operator with gateway credentials. Bearer auth gates entry; access control inside the gateway assumes the operator is authorized.
- Side-channel attacks on local LLM weights. Model integrity is checked at load, but not at every inference.
- Physical access to the machine.
- Threats specific to platforms we don't run on (we run local-first; cloud-specific threats aren't our model).
Listing the limits matters as much as listing the wins. A threat model that claims to defend against everything is a threat model nobody has actually walked.
Reporting vulnerabilities
Coordinated disclosure
Do not open a public issue for security vulnerabilities. Email security@legionforge.org.
We respond within 5 business days. After a fix is in place and users have had a chance to update, we publish a security advisory in the affected repo with the coordinated CVE if one was assigned.