No direct identity writes
HNPT consumes verified Shared Auth claims and owns its own product authorization. It does not mutate identity-provider storage.
Defensive by construction
HNPT separates authentication from product authorization, customer identity from operator identity, evidence from telemetry, and suspicious sessions from production reachability.
Each capability carries an explicit delivery state. We do not present a roadmap item as a deployed control.
The authentication proxy validates exact issuer, audience, client, realm, scope, and assurance contracts before HNPT authorization runs.
Integration in developmentHNPT remains authoritative for tenant membership, application roles, case access, quarantine scope, and response policy.
Contract availableCustomer and operator identities fail closed and never fall back to one another.
Safety invariantAttacker-controlled values are bounded at ingestion, parameterized in storage, encoded at output, and excluded from metric labels.
Safety invariantSynthetic workloads deny production data, credentials, and reachability while preserving reviewable session evidence.
In developmentDegraded identity, missing tenant context, ambiguous scope, stale leases, and unknown policy states do not silently become access.
HNPT consumes verified Shared Auth claims and owns its own product authorization. It does not mutate identity-provider storage.
This static site handles no credentials, sessions, provider tokens, introspection credentials, or customer evidence.
Build with us
Define what may be observed, what a quarantine can affect, how it expires, and who reviews the evidence before connecting a production system.