# Security Practices — Siglata

At Siglata, security and deterministic agent safety are core engineering principles.

## Architecture & Isolation
- **Isolated Execution**: All agent script executions run in isolated, memory-bounded environments.
- **Model Context Protocol (MCP)**: Standard Streamable HTTP endpoints with OAuth 2.0 PKCE authentication and granular capability negotiation.
- **Human-in-the-Loop Governance**: Mutations and bulk data alterations require human verification before committing to production workbooks.

## Vulnerability Reporting
We welcome responsible security disclosures. Please report security issues directly to security@mail.siglata.com.
