Safety & trust
Built for the reviewer who says no for a living.
Cirra assumes your security team is right to be skeptical of anything that can touch a production GPU fleet. So the safety model is structural, not aspirational.
No mutation verbs at baseline
The collector ClusterRole contains zero write permissions and no BMC, Redfish, PDU, or BMS credentials. Canary execution uses a separate, disabled-by-default service account scoped only to the approved action.
Deterministic guardrails
Abort and rollback logic is a deterministic policy engine — never a forecast, never an LLM. A guardrail breach or lost verification signal forces rollback according to the approved policy.
Hard constraints beat confidence
Safety, isolation, topology, and SLA policies cannot be overridden by a model score. High expected value never erases high operational risk.
Plans expire
Approvals are bound to an exact plan, policy hash, scope, and observed cluster preconditions. If anything drifts beyond tolerance, the approval is void and nothing runs.
Emergency stop is independent
Operator emergency stop and product disablement never depend on the intelligence engine being healthy.
Fail closed, always
No valid approval, exact policy hash, matching preconditions, or healthy guardrail stream means no mutation. Missing flexibility data makes actions less aggressive, never more.
Data minimization
Your workloads stay yours.
- ✓No source code, prompts, model weights, or request payloads — by design
- ✓Raw telemetry and topology can remain entirely in your environment
- ✓Labels collected through an allowlist; identifiers can be hashed
- ✓Egress deny-by-default; air-gapped report mode available
Trust-building evidence
Calibration you can audit.
Shadow precision
How often a proposed node release remained safe through the full predicted horizon.
Recall calibration
Whether 5% predicted recall risk actually occurs about 5% of the time.
SLO preservation
The measured gap between predicted and observed service outcomes.
Campaign fidelity
Predicted-versus-measured distributions across every repeated execution — variance reported, never hidden.
Skeptical? Good.
Ask for the security package: threat model, SBOM, signed images, RBAC manifests, and the full audit-ledger schema.