Skip to content

Trust lives in the boundaries.

Our current product principles, what is implemented by product, and what is still roadmap work.

Moonwind hero film 5
Monochrome editorial image of layered boundaries and a visible approval point
Moonwind is early. We separate current controls from planned controls.

Set the boundaries before the run.

These are current product principles, not a claim of finished compliance. Product-specific controls are described separately.

Contain execution

Scope agent runs to configured workspaces and make credential boundaries deliberate.

Teams should be able to define where work happens, what context is available, and which environment variables, integration settings, and workflow policies govern access.

Minimise exposure

Keep raw work local by default and configure tools with the least privilege a workflow needs.

BuilderGraph is designed so raw transcripts, source code, full prompts, and command outputs stay local unless a user explicitly chooses otherwise.

Keep review visible

Surface run state, tool usage, approvals, retries, and handoff metadata for operator review.

Important actions should pause at explicit approval gates instead of disappearing inside invisible automation.

What happens to your data, right now.

This page separates configured access, human controls, and roadmap work so planned features are not presented as current behavior.

Current product behavior

No future tense disguised as fact.

Configured access

Code and transcript access begins with what you configure.

Northstar Build works with the repositories, isolated workspaces, workflow rules, and scoped credentials you configure. BuilderGraph is designed so local AI session analysis can run without uploading raw transcripts, source code, or full prompts by default.

Human control

Approval should remain a visible product surface.

Important actions should be gated by review, approval, and clear operator feedback. Moonwind products prioritize approval surfaces over invisible automation.

Security roadmap

Early-stage status belongs in the trust model.

Moonwind is early. As the platform matures, security documentation, deployment guidance, audit controls, and compliance posture will become more formal and product-specific.

Important actions should be gated by review, approval, and clear operator feedback. Trust depends on making those moments visible.

Found something we should investigate?

If you believe you have found a security vulnerability in Moonwind, report it directly. We take reports seriously and review them with the team.

security@moonwind.io

Bring your hardest security question.

Tell us your deployment model, data constraints, and required controls.