This is the strongest security claim the product makes, and no single-vendor architecture can match it.
Three refusals, three operators
- The SaaS refuses to issue an out-of-scope intent.
- A separately operated Intent Scanner refuses to counter-sign one.
- The customer’s own endpoint refuses to accept one.
ExaCollab has no management, configuration, telemetry or update channel to the scanner. It cannot reconfigure it, silence it, or ship it a new version.
What a compromise buys an attacker
A total compromise of ExaCollab yields the ability to ask, and nothing else. The scanner still declines to counter-sign, and the customer’s endpoint still declines to accept. Compromising the control plane does not compromise the estate, because the control plane was never the thing holding the door.
Zero software in your estate
ExaCollab ships a contract, not an agent: protocol, schemas, a reference implementation, a conformance suite and an attestation format. You build your own DEV environment, deploy and operate your own integration endpoint, and run development in your own tooling. Nothing of ours runs next to your production systems.