Skip to main content
Praxa is a managed Cloudflare/Supabase service. The public execution gateway is a versioned client boundary in front of privileged runtime and database authority; it is not a separately self-hostable agent runtime.

Current partner-preview boundary

  • personal-tenant praxa_sk_ authentication and exact endpoint scopes;
  • strict minimal durable tasks;
  • customer-safe run and lifecycle-event projections;
  • cooperative cancellation requests;
  • evidence-bounded usage readback;
  • fail-closed bundled funding reservation and settlement;
  • no public prompts, private reasoning, raw tool arguments, credentials, executor leases, provider cost, or margin fields.
Automatic signed webhooks and bearer webhook management are active for admitted personal tenants. Exact browser-action approval remains pending. Separate production canaries have proved cancellation final states and authenticated canonical-host, alias, and deep-link preservation. The deployed portal authentication path is limited to email-link/OTP fragment callbacks, a persisted browser session, and durable legal acceptance; it does not activate the unavailable enterprise surfaces below.

Approval truth

Praxa’s existing product has multiple mature fail-closed approval domains. The first source-ready public approval is narrower: an immutable browse_session_act action whose exact instruction/steps, target host, and digest can be re-derived. Unsupported approvals are suppressed and refused. That does not mean every committing action gates through public /v1, or that a unified configurable policy engine is live. Generic tool approvals, policy packs, peer review, and organization approval roles remain unavailable.

Tenant isolation truth

The live public preview is personal-only. Server-derived tenant authority, tenant-bound run reads, and evidence-bounded usage are part of the current boundary. Organization execution, per-organization key authority, formal fabric isolation attestation, tenant-specific Vectorize/DO audit proof, and enterprise data-residency controls remain separate gates. Praxa’s existing organization RLS and custom-agent isolation are relevant foundations, not proof that every new public route has completed an enterprise isolation audit.

Receipts and learning

Current public run/event/usage projections and internal task events are not a mature receipt. Hash-chained evidence, policy-version linkage, approver identity, verification provenance, SIEM/PDF export, consent/training labels, and customer-visible learning controls remain roadmap work. Do not claim cross-tenant routing learning, content exclusion, or opt-out properties as public execution guarantees until their implemented data path and governance contract are independently verified.

Deployment options

Self-hosting is not on the roadmap because the runtime depends on managed Cloudflare primitives. Dedicated deployment is an enterprise direction, not a current substitute that can be purchased today.

Enterprise gaps

SSO/SAML/OIDC, SCIM, organization key administration, policy authoring, connector grant editing, centralized broker revocation, organization receipts, Evidence/SIEM export, dedicated regions, and related SLO/abuse dashboards are unavailable until explicitly activated and verified.

See also

Last modified on August 14, 2026