Skip to main content

Platform / Security Fabric

What a compromised agent still cannot do

Fourteen invariants define the boundary. Each one is backed by an executable test that has to both allow and deny — an invariant nobody can show the deny path for is not counted.

The assumption everything rests on

The model and the agent process may become fully compromised. The surrounding system must still constrain what the compromised agent can access, communicate, delegate and cause in the real world. Every control here sits where the agent cannot switch it off — in the sidecar, the gateway, the container runtime and the database, not in the prompt.

The fourteen invariants

13 of the fourteen are HELD. S4 is PARTIAL and is listed as such. An invariant is not satisfied until a test demonstrates the allow path and the deny path and the resulting external state is checked; anything not demonstrated is reported as not run, never as held.

  • S1Production credentials never enter LLM or agent reasoning contextHELD
  • S2Agent workloads have no unrestricted network egressHELD
  • S3Policy cannot be bypassed via curl, socket, node, shell, child process, MCP, IPv6 or DNSHELD
  • S4Every agent has a distinct short-lived workload identityPARTIAL
  • S5Agent-to-agent trust is never implicitly transitiveHELD
  • S6Delegation may narrow but never increase authorityHELD
  • S7Sensitive effects require authorization bound to the exact canonical actionHELD
  • S8Changing the target or parameters after authorization invalidates itHELD
  • S9Authorization is short-lived, single-use, nonce-bound and replay-resistantHELD
  • S10Higher-sensitivity data may not flow into a lower-clearance sinkHELD
  • S11Local enforcement continues without a control-plane round-tripHELD
  • S12Expired or unverifiable security state fails closedHELD
  • S13Every important effect produces verifiable evidenceHELD
  • S14The LLM may give semantic signals but is never final authorityHELD

What the evidence is right now

  • 1007 unit tests — 915 passing, 0 failing, 92 skipped — plus 135 gated tests run against a real Docker daemon, a real PostgreSQL server and a real gVisor runtime.
  • Every enforcement control is mutation-checked: the flag, check or database trigger it depends on is removed, and the specific test that should fail is confirmed to fail while the rest stay green.
  • This is locally verified on one host. It is not a production qualification, and it is not a claim about any other host.

What this does not do

It does not defend a compromised host

This protects against a compromised agent. It does not protect against root on the machine or a hostile kernel.

Confidential computing is not implemented

Keeping a signing key unreadable from outside an enclave is the only technology that would change the line above. It needs hardware this was neither built nor tested on.

It is not a certification

Not SOC 2, not ISO 27001, not FedRAMP. No certification is claimed. The open waiver is unsigned.

The full record — invariants, test matrix, phase report and the open waiver — is published alongside the release surface rather than summarised here.