Security model
Talons separates four authorities: account identity, a connection to one approved device, scoped capability grants, and exact consent for consequential actions. None implies the next.
Default posture
Assessment and bounded detection are the normal path. Adversarial probing is unavailable in the alpha and will require separate, explicit scope if introduced.
Bridge boundary
The hosted bridge is transport and durable coordination. A device authenticates itself; a model-provided device identifier is never accepted as authority. The first device to approve an account-scoped connection request wins atomically.
Updates
Hatch verifies a signed, product-scoped release manifest and exact artifact bytes before the Talons native installer can replace the app. Update approval is separate from GPT execution.
Report a problem
Use submit feedback in Talons or email security@owlandkestrel.com.