No public dependency
The authentication path must continue operating without internet access, hosted identity or licensing phone-home.
For defence and secure systems
A future assured RustyAuth profile could operate with local trust, device-bound authenticators and an entirely offline software lifecycle.
The operating reality
Personnel authenticate with organisation-issued, device-bound security keys. RustyAuth verifies every ceremony against local state, creates a revocable session and issues a short-lived token to the protected application. DNS, certificates, time, backups and operational evidence all remain inside the enclave.
The authentication path must continue operating without internet access, hosted identity or licensing phone-home.
Credential policy must distinguish issued, device-bound hardware from unmanaged or synchronised passkeys.
Installation media, updates, keys, recovery and audit export need reviewable offline procedures.
What the core contributes
RustyAuth establishes who authenticated and issues narrow claims. Sector-specific systems keep every business decision.
RustyAuth and its private data store can run within one controlled network.
WebAuthn binds authenticator output to the configured relying-party identity.
Invalid configuration, missing trust state and incomplete recovery prevent normal operation.
Honest boundary
Regulated infrastructure earns trust through evidence. These boundaries remain explicit while RustyAuth is pre-release.
RustyAuth does not replace
Production profile requires
Begin with evidence
RustyAuth is pre-release. Start with a synthetic account and a controlled evaluation—not a sole production identity dependency.