Remote content is untrusted.
Remote sites do not gain access to TAHAI privileged services merely because they are open in the browser.
Security architecture
Security work is being completed before packaging. TAHAI privileged services are isolated from remote sites, WebUI payloads require validation, and generic command or secret-retrieval interfaces are prohibited.
Remote sites do not gain access to TAHAI privileged services merely because they are open in the browser.
Mission references, service links, and local identifiers never grant access to TAHAI services or third-party providers.
IT Docs and PSA operations remain server-authorized. The browser is not an authentication authority and does not directly call PSA providers.
Prohibited interfaces
Browser-native tools must use narrow contracts, validated payloads, explicit permissions, and an audit trail.
Managed policy
The source includes a managed policy framework plus Windows Registry and GPO scaffolding. Protocol, extension, permission, diagnostics, privacy, and provenance evidence must pass before packaging proceeds.
Disclosure
Do not publish credentials, tokens, private customer data, or exploitable details in public issues. Use the contact path provided through TAHAI Web Services for responsible disclosure.