Threat Model
Source-specific identity, confidentiality, integrity and authorization boundaries.
Separate the security contracts
A Weave integration crosses local storage, key custody, discovery, transport, data verification and application authorization. Check the implementation of each layer and its selected feature profile. A signed data format alone does not establish that a receive path verifies it, that a channel encrypts it, or that a peer may act on it.
| Boundary | Current integration responsibility |
|---|---|
| Identity | Bind the expected public key and identifier to a trusted authority. Mock/simple providers are explicit test or limited adapters. |
| Payload authenticity | Verify the format-specific signature with the expected key before accepting content or acting on it. |
| Confidentiality | Select and verify an encrypted transport or payload codec for the exact path being used. |
| Authorization | Enforce scoped application policy and any configured replication admission controls. |
| Replay/freshness | Define a sequence, expiry or replay policy for the operation. A valid historical signature is not proof of current permission. |
| Availability | Treat peer discovery, network reachability and durable data retrieval as separate outcomes. |
Messaging
AgentMessage::new signs topic, payload and timestamp. The from identifier is outside those signed bytes. AgentMessage::verify accepts a caller-supplied public key, so the application must bind that key to the claimed sender.
MessagingManager currently bypasses SecretStream, sends plain TCP and forwards received messages without calling verify. Its historical encrypted-channel module comment is stale. Use the identity and messaging guide before enabling that path.
Replication and discovery
The SDK exposes paired private replication preflight and post-identity admission controls. Incomplete paired controls are rejected. Public announcements, peer discovery and sparse reads have their own record, writer-key and transport checks. A discovered peer count is not proof that an authorized replica has been obtained.
Read the networking, replication and DHT guides for concrete interfaces. Filament has unfinished runtime paths separate from the ordinary Weave workspace.
Hashes and encryption
Use each package's actual algorithm and encoding. weave-crypto uses Blake2s256 in its checked hash implementation; there is no universal rule that all network bytes are BLAKE3-addressed or signature-verified. Protocol-specific formats can use other hash functions.
Encrypted mailbox primitives and secret-stream transport are explicit integration surfaces. Their presence does not enable encryption in every SDK channel.
Keys, files and compliance
Protect signing keys and local process access. Check filesystem path and permission enforcement for the selected AgentFS operation. Vault and compliance modules include implementation gaps; a capability-shaped value, a Production type name, or an audit record is not an authorization or regulatory certificate.
Source declarations, feature conditions and reviewed caveats are available in the Rust reference. These docs describe checked source; a deployed security assessment requires the actual configured application and transport journey.