Typed capabilities
Every action has a defined input, operating range, approval policy, and stop condition.
Trust by construction
Power comes from reaching across the hardware stack. Trust comes from making every action bounded, authorized, attributable, and open to challenge.
What makes intervention credible
A reviewer should be able to see what was allowed, what happened, what the system inferred, and where uncertainty remains.
Every action has a defined input, operating range, approval policy, and stop condition.
The runtime enforces limits independently of the investigation’s preferred next test.
Actions, parameters, observations, and decisions are append-only and time-linked.
The case states what remains possible, what is ruled out, and what evidence would change the decision.
No one party both controls every action and unilaterally judges the result.
Actors, releases, receiving environments, and returned findings remain attributable.
One action boundary
The case names a capability, scope, and purpose.
The local owner approves action, bounds, and disclosure.
The runtime enforces the envelope and automatic stops.
Parameters and observations join the append-only ledger.
Only the agreed result and evidence references leave.
Privacy partitions
Raw workloads, broad fleet telemetry, credentials, and unrestricted infrastructure access.
Synthetic reproducer, scoped metrics, hashes, conditions, exclusions, and decisions.
Test implementation, design data, manufacturing records, and proprietary registers.
Signed result, stated confidence, limitations, corrective action, and custody.
When the answer is not clear
Zenobia does not guess. It reports what remains possible, what has been ruled out, and which next test is most likely to settle the decision with the least risk.
A safe hold decision with one named settling test is more useful than a false conclusion.
Continue the investigation
Discuss capability bounds, local authority, scoped disclosure, and attested replay.