User-owned identity
.gao identities are lifetime and portable. No core layer can revoke or hijack them.
Trust & Authorization
Identity is user-owned. Payments are user-signed. AI actions are capability-gated. Sensitive operations require explicit approval. Nothing important happens without authorization that can be verified after the fact.
.gao identities are lifetime and portable. No core layer can revoke or hijack them.
Payments are user-signed. No layer of the stack custodies user funds by default.
AI agents act under scoped capability tokens — not under blanket access to user data or funds.
Sensitive actions pass through policy gates before they run. Deterministic, auditable, and overridable by the user.
Receipts, refunds, agent actions, and approvals are first-class records — not afterthoughts.
Agents request approval for actions outside their scope. Nothing important happens without explicit authorization.
What Gao is not
Disclosure
Security issues are taken seriously. Use the disclosure channel rather than public issues for sensitive reports.