EAISENGINEERED AI SYSTEMS

Security / governance

Control is part of the architecture.

This page states the boundaries supported by current repository policy and keeps missing operational facts visible. It is not a certification or an external audit report.

Current baseline

Conservative permissions. Explicit approval. Recoverable change.

The public description must remain narrower than the actual verified practice. Planned controls are not presented as deployed controls.

Report a concern

The website operator is AMA Łukasz Kretowicz, a JDG. A dedicated security reporting address and incident owner remain pending. Until then, the public fallback is contact@eais.pl without a response-time promise.

Control register

Verified and pending boundaries

  1. 01

    Website operator

    AMA Łukasz Kretowicz, Polish sole proprietorship (jednoosobowa działalność gospodarcza), Emilewo 37/A, 62-640 Barłogi, NIP 6661935788, REGON 311552687. Firm, address and active status were confirmed in CEIDG on 2026-07-16; VAT status: Czynny. Dedicated incident responsibility remains pending.

  2. 02

    Access boundaries

    Systems are expected to separate applications, environments and credentials. Access to client data or production systems requires explicit scope and approval.

  3. 03

    Least privilege

    Agents, services and operators should receive only the tools and permissions required for the current task. Production access is not a default capability.

  4. 04

    Roles and human approval

    Sending external communications, publishing, deployment, DNS/firewall changes, secret rotation, deletion and access to client data require a human approval gate.

  5. 05

    Event logging

    Consequential decisions and release operations should produce a reviewable event record. PENDING OWNER DATA: the deployed log platform, access roles and retention.

  6. 06

    Secrets

    API keys, passwords, tokens, SSH private keys and production environment files are excluded from tracked source and belong in protected server files or a secret manager.

  7. 07

    Environments

    Production, local development and any future staging environment must have separate configuration and fail-closed external integrations.

  8. 08

    Validation and evals

    Structured output, testable contracts and scenario-specific validation are required before a workflow can reach a consequential action.

  9. 09

    Rollback

    Deployments require a known-good artifact, backup where state is involved and a tested route back to a safe version. Rollback must not delete production data.

  10. 10

    Data use

    Client data is not training material by default. Actual provider use, data residency and retention must be agreed for each engagement and reflected in the system design.

  11. 11

    Subprocessors

    PENDING OWNER DATA: publish only providers actually used for the relevant engagement or website flow, with their real role and boundary.

  12. 12

    Incident handling

    PENDING OWNER DATA: reporting address, triage owner, severity model, notification path and response targets. No response-time promise is made before that process exists.

  13. 13

    Assurance boundary

    EAIS does not claim ISO, SOC 2, external penetration testing or another certification unless current evidence is supplied. Repository rules and internal checks are not certifications.