Security validation report
Production Security Proof
Controlled adversarial suite against the live enforcement API. Same path customers use. Rates for this corpus only — not an independent third-party penetration test, and not a claim of universal protection.
Headline metrics
| Metric | Value |
|---|---|
| Attack held | 67/67 (100.0%) |
| Attack misses | 0 |
| False positives (benign blocked) | 0/1000 (0.00%) |
| Latency p50 / p95 / p99 | 62.4 / 87.1 / 182.1 ms |
| Latency mean (n=1069) | 65.94 ms |
| Bypass variants caught | 22/22 |
| Approval pause | YES |
| No exec until approve | YES |
| Bound action reject | YES |
| Fail-safe unreachable | YES |
| Audit integrity | 50/50 (100.0%) |
By capability
| Capability | Held |
|---|---|
| Prompt injection | 18/18 |
| Secret exfiltration | 20/20 |
| Unauthorized egress | 9/9 |
| MCP / tool drift | 3/3 |
| Trajectory attacks | 2/2 |
| Human approval | 1/1 (+ binding checks) |
| Blast-radius controls | 14/14 |
Before → after (product fix)
An earlier production run held 54/62 (87.1%) with secret exfiltration at 7/15 (46.7%). The firewall was hardened (encoding, fragmentation, GitHub/Slack/password policy). The original adversarial cases were not weakened. Retest: 67/67 with false positives still 0/1000.
What this does not prove
- Not an independent third-party penetration assessment.
- Not coverage of every encoding, language, or tool chain in the wild.
- Not a guarantee of 100% protection outside this corpus.