VAIS Boundary

Security for AI-enabled systems

Assume model compromise.
Constrain consequence.
Verify effects.

VAIS Boundary places a deterministic security boundary between AI agents and consequential tools. Authority comes from trusted policy. Observable effects are checked independently.

Download on GitHub

Current downloads are release candidates. Review the release notes before use.

01 / ASSESS

Understand the exposure.

Measure whether hostile context changes agent behavior and produces a security-relevant effect.

02 / ENFORCE

Keep authority outside.

Mediate tool calls using trusted task scope, least privilege, information-flow rules, and exact approvals.

03 / VERIFY

Check what happened.

Independently test observable effects against declared security conditions.

Evidence

Measured, and bounded.

Every figure below comes from one recorded campaign against local models. Nothing here is an estimate, and the limits are stated beside the results rather than below them.

What was measured

  • 14 of 15 models completed the full stage. SmolLM3-3B stopped at a generation-validity gate and is excluded from completed-model conclusions.
  • 4,603 of 4,605 staged episodes were evaluable. The two remaining target failures are left unevaluated, not counted as defended.
  • Zero protected invariant violations observed by the independent verifier across the campaign.
  • 2,207 of 3,360 attacked protected workflows retained utility (65.7%).

What it does not show

  • Not proof of universal security. One campaign, recorded model builds, one local runtime.
  • 65.7% is not the cost of enforcement. In the paired control, discordant pairs split almost evenly — 25 success-to-failure against 28 failure-to-success.
  • One enforcement surface ships unmitigated: the decision reason returned to the caller can disclose which argument a contract binds.
  • In a separate lab experiment both pre-registered primary outcomes failed to validate, and a content-filter guardrail matched the enforced arm's catch rate. The difference showed up as cost, not catch.
  • Release candidate software. Not production hardened.

These three files are byte-identical to the assets published with the release, so their SHA-256 values match the release SHA256SUMS.

Get in touch

Working with
AI agents?

Questions about using VAIS Boundary or integrating it with your tools? Send a message.

For vulnerability reports, follow the security policy.

Contact details and message

Your message is processed by Web3Forms.
How your details are used