Trust and Coverage

Security claims should be inspectable.

CodeMarine is building a proof-backed coverage model that names the agent, surface, mechanism and operational state behind every preventive claim.

This page is a public product contract. It distinguishes current foundations from beta adapters and planned proof systems.
Surface coverage Target product view
CLAUDE CODE · PAYMENTS-API4 SURFACES

Workspace code changesDeterministic scan path

Current

Destructive shell commandsHook capable, no live proof

SETUP NEEDED

Native web actionsNo local interception path

NOT COVERED

CodeMarine MCPMediated tool path

Beta

This view is illustrative. The typed status authority and live proof registry are planned.

Trust principles

Say exactly what the control can prove.

Code scanning, runtime prevention, after-effect detection and recovery are different capabilities. CodeMarine will not collapse them into one protected badge.

01 · Specificity

Coverage is per surface

An agent can have guarded shell actions and uncovered native browser actions at the same time.

02 · Proof

Installation is not enforcement

A hook file can exist while the host never invokes it. Guarded requires a current live-host canary.

03 · Separation

Health is not capability

A mechanism may support blocking but still be disabled, stale or disconnected in one workspace.

Human status language

Six states with distinct meanings.

The planned UI derives these labels from typed capability, mechanism and health data. Screen copy must not mint them independently.

Guarded Planned

A supported blocking mechanism is active and has current matching proof.

Alerts only Planned

CodeMarine can observe or warn but cannot authoritatively block this protection.

Setup needed Beta

A capable path exists but installation, permission or proof is incomplete.

Problem Planned

A previously configured mechanism is stale, unreachable or failing.

Off Planned

The protection has been disabled by an authorized setting.

Not covered Current

CodeMarine has no structural interception path for this action.

Live proof

Guarded should expire when reality changes.

A valid proof must bind the host and protocol, adapter configuration, CodeMarine build, policy revision, workspace and adversarial test. A host update or configuration change invalidates stale proof.

The live canary and proof registry do not exist yet. Current hook surfaces must not be presented as Guarded.

Proof record Planned schema
PROTECTIONdestructive_shell_commands
Host + protocol
Bound
Adapter hash
Bound
Policy revision
Bound
Workspace
Bound
Harmless canary
Passed
Expires
23h 14m

Example only. A real proof also records build revision and the successful test identity.

Data handling

Keep evidence useful without turning it into a leak.

The action guard is designed around classifications, reason codes and fingerprints. Raw commands and secret contents should not become routine telemetry.

RETAIN
  • Stable reason and category codes
  • Decision fingerprint and severity
  • Agent, tool and workspace attribution hashes
  • Mechanism and policy revisions
  • Outcome and timestamps
DO NOT RETAIN
  • Raw commands by default
  • Environment variable values
  • Secret or credential content
  • Database connection strings
  • Unbounded tool payloads
Capability ledger

What exists now and what is being built.

This ledger avoids fixed pattern counts and universal enforcement claims. It should become machine-generated from owned product evidence.

AreaClaim boundaryStatus
Deterministic code scanningUnified local-first scan path with structural confirmation in supported languages Current
Supply-chain and AI artifact scanningMultiple package ecosystems plus selected MCP, rule and skill artifacts Current
Destructive action evaluatorDeterministic command evaluation with sanitized verdicts Current
Provider action adaptersDefined shell or write paths. Setup and provider limits apply Beta
Proof-backed Protection CenterPer-surface status, live canaries, event history and critical alerts Planned
MCP and API authority gatewayStructured remote tool policy and scoped credentials Planned
Frontier investigation loopBounded context, provider routing and deterministic patch gate Planned
Enterprise governanceSSO, SCIM, organization RBAC and compliance reporting Planned
Security contact

Found something we should know?

Send security reports to the CodeMarine team. Include the affected version, reproduction details and a safe way to contact you.

Report a security issue
Do

Use a minimal reproduction and avoid accessing data that is not yours.

Do not

Publish active exploit details before the team has had a reasonable chance to respond.

Expect

An acknowledgement and a request for any missing details. A formal response SLA is not claimed yet.

Early access

Evaluate CodeMarine on the evidence, not the headline.

We will show what is current, what needs setup and where no preventive path exists.

Sarge, the CodeMarine guardian