Credentials stay outside the agent
Sensitive git, infrastructure, backup, and delivery operations are executed by native Broker code rather than the coding agent.
Safety by architecture
Waymark’s safety model limits what an agent can reach, makes sensitive actions independently enforceable, and keeps recovery outside the agent’s control.
Core
Plans, scoped context, bounded requests, and safe summaries.
Broker
Credentials, git, processes, network writes, evidence, and recovery.
Implemented principles
These are the architectural guarantees Waymark is being built and tested around—not generic trust language.
Sensitive git, infrastructure, backup, and delivery operations are executed by native Broker code rather than the coding agent.
The agent-facing Core module cannot import the Broker’s credential stores or privileged executors.
Agent processes operate inside managed worktrees without access to repository internals, other worktrees, or recovery stores.
Repository instructions, prompts, local documents, and artifacts pass provenance and content-bound policy checks before launch.
Evidence stores bounded identities, hashes, verdicts, counts, timings, and summaries. Source, diffs, transcripts, output, and secrets remain local.
Stale proof, unsafe scope, credential leakage, uncertain production identity, or failed cleanup stops the workflow.
Automatic delivery can remove a routine human pause. It cannot remove immutable artifacts, exact target proof, staging and rollback evidence, scoped commands, health verification, or recovery coordination.
Private preview
Join the Studio waitlist for product progress, early previews, and launch access.