What it gives you
- Fail-closed local-only migration for existing collections
- Conservative loopback, LAN, VPN, proxy, redirect, and remote classification
- Independent authentication, authorization, and egress gates
- Most-restrictive policy propagation across mixed evidence
- Derived Capsules, traces, exports, and records retain source policy
- Stable content-free denial reasons across CLI, REST, MCP, SDK, and Web
- Bounded local redacted audit receipts with inspect and purge controls