Skip to content
◇ AirawatOS Developer
🚧 Under development — this portal is being built track by track. Content will keep growing, and some sections are still placeholders.

Build

Components run inside a Clean Room

Your component is confined to a clean-room contract: it may touch only what it declared up front, and the platform enforces that. The lightest components reach the outside solely through a single guarded channel — the broker — which lets through exactly what was declared; heavier components run in a locked, certified container holding just their declared capabilities. Either way, anything you didn’t declare is out of reach. (The fullest form — a component with literally no socket at all — is the target tier, still being built; see Zero-Trust.)

You declare five things

You write these in the component’s description file (see Anatomy). They become the component’s permissions — checked when it’s signed, and enforced every time it runs.

This is the core safety promise: a tenant can read your permissions before installing you, and know that is the complete list of what you can do. The Zero-Trust deep dive has the details.