Provider egress allowlist gateway

Outbound network calls can only go to explicitly allowed providers.

TESTED , rung 3 of 8 Recorded 17 September 2026

Technical

What it is

Provider egress allowlist gateway: outbound HTTP/WS is routed through one gateway that enforces the constitution's provider allowlist.

Truth ladder

Where it stands

Rung 3 of 8: TESTED

Automated tests exercise it in isolation, often against fixtures.

Project record: IMPLEMENTED

  1. CONCEPT Designed or specified. No working code yet.
  2. IMPLEMENTED Code exists. Nothing has demonstrated that it behaves correctly.
  3. TESTED Automated tests exercise it in isolation, often against fixtures.
  4. INTEGRATED Wired into the rest of JARVIS and tested across component boundaries.
  5. PRODUCTION-REACHABLE The owner can reach it through the real runtime path, not only through a test harness.
  6. LIVE-PROVEN A bounded probe ran the real code path on a booted JARVIS on the real machine and recorded evidence. The project treats live evidence as expiring after 24 hours, so every live reading here shows the date it was taken.
  7. FORMALLY VERIFIED Its critical property is checked by a proof or exhaustive verification.
  8. RELEASE-QUALIFIED Passed every qualification gate for a named release.

Limits

Limitations

  • A probe of the real code path passed and wrote evidence (2026-09-17), but it did not demonstrate a booted process on a real port, so the project itself refuses to call it LIVE.

Record

Status history

  1. TESTED , rung 3 of 8 Recorded state: IMPLEMENTED

Only states recorded in the public export are listed. Earlier states may exist in the project’s private ledgers.

Neighbours

Related capabilities