Deployment boundaries

FrogNet secures its network. Internet RAM vendors secure their Regions.

These are separate responsibilities. The Living Network has concrete LAN and inter-site security properties. Internet RAM does not inherit a universal security policy from the fabric.

Local pond

A local FrogNet application can stay on the LAN. It does not need a public Internet application endpoint. An attacker outside that LAN must first obtain access to the local network before reaching the application surface.

Specification: §12 Security and trust boundaries

Brokered sites

Every cross-site packet traverses the broker. The site-to-broker legs are WireGuard tunnels. The application itself still need not publish its own Internet-facing protocol or endpoint.

Internet RAM

Security is the vendor's responsibility. The Region owner decides how the service is exposed and what authentication, authorization, encryption, validation, auditing and rate policy it requires. Those choices are not properties of the RAM fabric.

Internet RAM is not a security architecture.

Network Shared RAM defines how programs address and use shared state. It does not prescribe a universal security model for an Internet-facing Region. A vendor may place a Region behind whatever controls its application and threat model require. FrogNet does not silently supply or mandate those controls.

The broker boundary is explicit, and deliberately small.

Specification: §12 Security and trust boundaries · §7 Internet extension and broker

Each side establishes its own WireGuard relationship with the broker. The broker therefore terminates separate tunnel legs: traffic can be decrypted at one tunnel interface, forwarded by the kernel and encrypted into another. A person controlling a live broker can observe plaintext IP traffic at that forwarding seam. If confidentiality must survive compromise of the broker itself, it belongs above that transport boundary.

That is the exposure. The mitigation is what FrogNet deliberately does not put on the broker. It is transit, not authority. It is not the FrogNet database, Memory authority, service-election authority, semantic engine or a member of the pond. It does not hold the application database, application Memory, user-password database or an authoritative inventory of FrogNet names and network state. Stealing the broker does not hand an attacker the network's durable state or central control because those things were never centralized there.

What live compromise can do

Observe traffic crossing the forwarding seam, disrupt or deny that path, and attack whatever tunnel relationships and local broker process state are present while the machine is under control. FrogNet does not pretend otherwise.

What the broker is denied

No application datastore. No FrogNet Memory authority. No service-election authority. No central user/password store. No authoritative naming or topology database. The design limits the durable prize instead of making the broker a second copy of everything valuable.

Loss of the broker or WAN path also does not stop the surviving local ponds from operating. When connectivity returns, discovery can rebuild the reachable network.

Semantic transport is a wire property, not a security control.

Specification: §11 FNWP-1 and BLDC-1 · §12 Security and trust boundaries

SAME, DIFF, learned structure and tokens can mean that the bytes carried inside FrogNet are not repeated copies of the application's original representation. That can make captured internal traffic less directly recognizable, but it is not a confidentiality guarantee and is not counted as one.

See the semantic and Memory contracts →