Injection firewall
A regex fast path sheds high-volume attacks at zero ML cost; an embedding-based semantic classifier judges the subtle ones. Three operating modes tune recall against false positives.
A dual-layer control plane for autonomous agents — millisecond prompt-injection firewalls off-chain, verifiable identity and tamper-evident evidence anchoring on-chain.
99.0% AdvBench strict|41.88 ms p95 under attack
Browser demo running a handful of public rules. The production gateway runs 40+ real-time controls server-side, with an embedding classifier behind the regex fast path.
AdvBench block rate · strict
benchmark run · aug 2026
p95 latency while blocking
chaos report · aug 2026
real-time security controls
in one gateway pass
OWASP LLM Top 10 (2025)
risks covered · test snapshot
Each layer is independently tested and artifact-documented. Together they close the attack classes that ship in the wild today.
A regex fast path sheds high-volume attacks at zero ML cost; an embedding-based semantic classifier judges the subtle ones. Three operating modes tune recall against false positives.
Morse, Braille steganography, Base64, hex, binary, ROT13, homoglyphs — normalized before classification so payloads can't hide behind an encoding layer.
Responses scanned before egress: PII redacted, XSS/SQL/shell fragments blocked, system-prompt leakage caught, optional watermarking applied downstream.
Rate limiting that closes instead of opens under failure, chaos-tested degradation, and SLO checks that run in CI — when parts die, the gateway fails safe.
The execution layer decides in milliseconds whether traffic is safe. The trust layer makes an agent's identity and track record independently verifiable.
Every figure on this site cites its dated repository artifact — and the proof page publishes full benchmark tables, not just highlights.
3,211 prompts across 8 public datasets, August 2026. AdvBench 99.0% strict, JBB PAIR+GCG 98.7% — and Do-Not-Answer's 57.1% published too, because selective reporting is how trust dies.
External pentest closed March 2026, zero open critical/high findings. Internal off-chain and contract audits remediated July–August 2026. No current third-party audit — stated plainly until Q3's external review lands.
Nine-contract suite on Base Sepolia and Monad testnet. Anchoring runs simulated-by-default. No mainnet claims anywhere on this site — check us.
The full platform runs as a managed cloud service — no setup, no maintenance. Onboarding opens soon.
A managed gateway with usage-based tiers is in the works. When the meters run live, prices get published here — from the metering service, not from marketing.