Bounded execution
Kenogram security boundary
The implementation makes admitted mounts, networks, secrets, resource limits, lifecycle, and persistence explicit and inspects the resulting runtime.
Disclosure boundaryA container is one boundary, not a universal safety claim. Kenogram is not a prompt filter, does not certify a hostile host, and does not protect authority deliberately admitted by the operator.
Verified against commit 4cd6551971a7.