Markings & access control
Control-based access (CBAC): access markings live on the object and enforce at query time. A user sees a value only if their markings clear it — the same rule in Foundry and Nexus.
TELOS SECURITY · GOVERNANCE
01. CONTROLS
Each cell above is backed by a real control. These are the four that do the most work — and how Telos states what it does without overstating.
Control-based access (CBAC): access markings live on the object and enforce at query time. A user sees a value only if their markings clear it — the same rule in Foundry and Nexus.
Every read, write, and promotion is recorded to an immutable, queryable log. Retention windows are configurable to your policy — including multi-year holds for regulated data.
Run Telos inside isolated or air-gapped networks where data never leaves your boundary. The control plane deploys to the environment rather than pulling data out of it.
Telos gives you the lineage, markings, and audit trail compliance frameworks ask for. We state capabilities, not certificates we don't hold — specific attestations are shared under NDA during access review.
TELOS SECURITY · REQUEST ACCESS
Tell us your markings, retention rules, and isolation needs — we'll walk through how Telos enforces them.
Request access