I didn't expect the hardest security decision in a compliance engine to be about outbound network calls. It was. Opencomplai's services occasionally need controlled external connectivity. Fetching a model card. Hitting a registry. Whatever a given integration requires. The obvious options are two. Let every service make arbitrary outbound requests, which is bad for anything touching legal evidence. Or block everything and special-case exceptions inline in each service, which is a maintenan...