Trust boundary

Security behavior you can reason about.

APIZ is designed as an enforcement layer, not a secret-distribution tool. Denials are explicit, credential release is decision-bound, and recovery preserves identity without silently weakening controls.

01
Secrets stay server-side
Clients receive APIZ-scoped temporary credentials. Adapters and Scripted Policy never read decrypted upstream credentials directly.
02
Decision-bound release
Credential validation, Policy, adapter validation, credential overwrite, Secret Broker checks, and required Audit evidence remain on every execution path.
03
Fail closed
Authorization, subscription coverage, Policy runtime errors, required evidence failures, and revoked Membership credentials stop before upstream contact.
04
Redacted evidence
Access and Audit Logs retain decision evidence without raw provider payloads, tokens, card data, upstream secrets, or credential hashes.
Control Plane
Identity, Team governance, configuration, billing, and Audit
Data Plane
Credential admission, Policy, Secret Broker release, and upstream proxy
Commercial gate
Free allocation or provider-reconciled paid coverage before execution