Physics, not policy.
Most platforms promise the model won’t exfiltrate your credentials. We make it impossible. The Opaque Handle Pattern replaces every OAuth token in the model’s context with a cryptographically random, time-bounded handle scoped to a single agent run. The real token never enters the model’s address space. Seven boundary layers. Each one kernel-enforced. Each one inspectable.
Inspect the seven layers