Skip to content

SASH — Scoped Authorization for Sensitive Handling

Software DOI Technical Preview DOI

SASH is an open, implementation-independent protocol for keeping protected data and privileged capabilities outside an untrusted Requester while preserving useful processing, authorized effects, and explicit completion or reconciliation evidence.

Its core principle is simple:

Requesters ask for effects, not secrets.

SASH defines interoperable objects, state transitions, cryptographic bindings, protected views, destination controls, effect profiles, and evidence receipts. A deployment may integrate vaults, identity systems, privacy engines, sandboxes, gateways, or automation platforms without turning any of them into an implicit protocol dependency.

Protocol surface

Technical preview

Scope and limits

SASH does not claim to invent generic agent mediation, credential use without model exposure, tokenization, pseudonymization, or privileged execution. It is not an IETF standard, a universal anonymization guarantee, a production-security certification, or a legal-compliance conclusion. Every assurance statement is bounded by the declared profile, implementation, deployment, evidence, and remaining trust assumptions.

The protocol and its machine-readable artifacts are open for implementation and evaluation. See the license files for the applicable Apache-2.0 and CC BY 4.0 terms.

About

SASH Protocol: scoped authorization for sensitive handling

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages