Trust

Trust should be inspectable before it becomes a claim.

TRUST / 03

Daulat treats policy, signed execution, customer-controlled boundaries, and provenance as part of the platform path—not as a layer bolted on around it. Every control below sits in the path a run has to take.

Implemented control model

Controls live in the execution path.

These are product mechanisms. Whether they satisfy a particular organization’s obligations still requires scoped technical, legal, and operational review.

01 / IDENTITY

Identity + attributes

Organization and user identity provide the subject for attribute-based policy and accountable action.

02 / AUTHORIZATION

Policy before execution

Participation, purpose, asset access, consent, licensing, and custodian approvals are evaluated before work begins.

03 / SUPPLY CHAIN

Approved signed workloads

Execution uses platform-approved, signed images and pinned assets rather than arbitrary code submitted at run time.

04 / BOUNDARY

Customer-controlled execution

Approved work runs in the environment governed by each participant; protected data need not be pooled centrally.

05 / RUNTIME

Isolation + approved egress

Runtime policy constrains resources and permitted network behavior within the execution boundary.

06 / EVIDENCE

Audit + provenance

Policy decisions, versions, runtime identity, signatures, outputs, and lineage support technical review and reproducibility.

Controls in motion

Controls are easier to judge in motion than in a list.

The healthcare journey puts each control where it actually sits: authorization before execution, signed runtimes pinned by digest, custodian-governed boundaries, and lineage at the end.

Customer-controlled deployment

Your environment is the execution boundary.

Your cloudParticipants run in their own cloud account, under their own controls, network policy, and key custody.
On-premisesWhere data cannot leave the building, the execution node runs in the building.
Hybrid or mixedInstitutions participate as they are, without normalizing onto one provider first.
Egress onlyThe node dials out to the control plane. It needs no inbound route into your network.