Get started

nine banked trust bars

Nine adversarial trust bars. Each one attacked, each fix proven on the running system, each result independently recomputable from signed evidence.

Not a green checkmark. A ladder of bounded, falsifiable exams, each banked as an immutable milestone and each raising the bar on the last, where the attacks, the fixes and the proofs are all on the public record.

why a ladder

Why a ladder, not a single moving bar.

A single moving bar is unfalsifiable: every pass spawns a harder test and the finish line never arrives. So each bar is banked on pass as an immutable, versioned milestone, and the next bar raises the standard additively. A banked bar is never redefined. Ten out of ten is an asymptote, never a gate. A bar is banked only when an independent verifier recomputes the evidence chain and the recompute gate passes. Quox does not publish its own scoreboard.

the spine

Nine bars, each one harder than the last.

Every bar below carries a named attack, a named fix verified on the running system, and an engagement id you can trace. None is redefined once banked: the next bar only ever adds to what came before.

v1

Release Gate

live on /security
Certifies
No bypassable release-blocker on the frozen release surface, with every trust-property boundary verified on the running systems, not just the source.
Attack
An independent adversarial pass over the whole frozen release surface: collector, auth, the quoxagent fleet and bastion.
Fixed live
Thirty-three findings in the cycle; the release-blocking set remediated and deployed. The two deploy-pending blockers (bastion keys and deploy-grant, quoxagent job-envelope replay) were deployed live and resolved.
Honest debt
Plugin backends still share the internal service key (carried to a higher bar); some policy routes trusted a caller-supplied org id (carried to v1.2).
T1 evidence binds the effective actionT2 fail-closed gatesT3 durable intent and recoveryT4 reviewable authorityT-AUTH authorization lifetime and single-useT7 tenant and resource isolationT8 signature integrityT9 complete mediationT-CONF secret confidentiality

engagement ENG_01M3R1RVXHFNRB3GF6CAFNRB3G

Banked · live on /security
v1.1

Parity & Repeatability

live on /security
Certifies
What was audited is what is running, provably (source equals artifact equals running, or the gap is named with a remediation path), and the v1 pass repeats on a second independent attempt.
Attack
Byte-identical hash parity on the running collector, plus a full second independent pass over v1's invariants.
Fixed live
The repeatability pass caught a high-severity cross-tenant hole the first pass missed: a set of compliance tools trusted a caller-supplied org id, so a user in one org could read or write another org's compliance artifacts via chat. Fixed, deployed, verified live, red-proven.
Honest debt
Build-provenance observability is incomplete: most components cannot yet report their running generation (the fleet agent now can). Fleet at twenty of thirty-seven current, seventeen unreached.
T7 tenant isolationParity: source equals artifact equals runningRunning generation observable

engagement ENG_01M3X057C151EGY8PMZE51EGY8

Banked · live on /security
v1.2

Complete Mediation

live on /security
Certifies
Every effect-producing entry point across all surfaces passes exactly one reviewed gate, enforced and not merely asserted.
Attack
A bounded sweep enumerated every effect path across five surfaces: collector tool executors, connector HTTP routes, the chat widget, plugin tools, agent jobs and dev-seams, and bastion key and exec paths.
Fixed live
A conformance test now proves every effect-verb tool sits in exactly one reviewed bucket, green in continuous integration. Four fixes closed the gaps the sweep found, all deployed with red-proven pins.
Honest debt
Paid tools have no per-org cost-budget gate yet (no budget infrastructure exists; an honest TODO carried to v1.8), plus two weaker fail-open hardening items.
T9 complete mediationT4 reviewable authorityT2 fail-closed gatesT3 durable intent

engagement ENG_01M3WC959AS5XWEGCGVBS5XWEG

Banked · live on /security
v1.3

Resilience

live on /security
Certifies
Every mandatory-dependency fault leaves the effect path fail-closed or durably queued, with visible degradation, no double-effect, and recoverable incomplete executions.
Attack
Fault-injected every mandatory dependency across five surfaces: evidence store down, policy service down or null, external-effect crash after send, collector restart mid-dispatch, agent restart.
Fixed live
Fail-closed evidence and policy gates, a durable execution ledger (crash becomes outcome-unknown, never a silent retry) and an atomic single-use claim, all verified live in the running container. The real fix: the agent replay set was in-memory only, so a restart reopened the replay window; now durable, red-proven, deployed.
Honest debt
The durable write is best-effort (a write failure plus a restart is a rare compound reopen; a fail-closed flag is available); the agent heartbeat loop has no backoff leg yet.
T2 fail-closed under dependency failureT3 durable intent and recoveryT10 durable across restartVisible degradation

engagement ENG_01M3WS3FTHXGWC5A3RASXGWC5A

Banked · live on /security
v1.4

Confidentiality & Supply-chain

live on /security
Certifies
No secret or cross-tenant data leaks into logs, responses or transcripts, and every deployed artifact's provenance is verifiable or named with a remediation path, with install integrity failing closed.
Attack
Hunt for secret leakage across logs, responses and transcripts, and audit the supply chain: dependency pinning, install integrity, artifact provenance.
Fixed live
Credentials resolve by reference and are never returned, receipts are content-free, mandatory audit is always stored. One real leak fixed (raw tool-input logging, which was live in production) and one unpinned dependency pinned; install integrity already fails closed.
Honest debt
Build-provenance observability: most service health endpoints return a version number, not a git commit. The remediation spec is written; it is a supervised build-pipeline change, not an overnight one.
T-CONF secret and data confidentialityT-ART artifact and runtime integrity

engagement ENG_01M3X1XBG75GX72VJCVA5GX72V

Banked · live on /security
v1.5

Injection / Containment

live on /security
Certifies
Assume the reading model is fully compromised: it cannot reach an interpreter, expand recipients or permissions, exfiltrate to an unbounded destination, or let untrusted content carry authority. This is not a claim of universal injection immunity (a stated non-goal); it is a claim that the enforcement boundary sits outside the model.
Attack
Treat every model output as hostile: try to reach a shell, SQL or template interpreter, widen recipients, exfiltrate, or smuggle authority through content.
Fixed live
A single governance chokepoint gates every tool call by effect and not by provenance, no model output reaches an interpreter, and approved email recipients are fingerprint-bound. One escalation fixed: a navigation tool let a model-controlled URL reach loopback, private and cloud-metadata addresses ungated (a server-side request forgery), now blocked.
Honest debt
DNS-rebinding (a hostname that resolves to a private address) is not yet blocked; two URL validators to unify.
T5 untrusted input and output containmentT6 egress and exfiltration bounds

engagement ENG_01M3X30DKDFJB6D76W1FFJB6D7

Banked · live on /security
v1.6

Evidence Tamper-Evidence

live on /security
Certifies
The audit trail cannot be forged, omitted, reordered or edited without detection, the commitment binds the effective action (no attacker-writable field verifies green), and an independent recompute fails closed on tamper.
Attack
The most on-thesis bar: attack the evidence itself. Forge an entry, delete one, reorder, tamper the tip, rewrite a field outside the hash.
Fixed live
The chain binds sequence, previous hash and payload hash; verification detects forgery, omission, reorder and tip-tamper with no swallowed errors, and no mutation path exists on the ledger. The witness commitment binds the effective action (the historical payload-exclusion bug is fixed). An independent recompute refuses to publish on mismatch. A clean exam, with the missing gap-detection test added.
Honest debt
Two ledger columns (org and tags) sit outside the chain hash, so a raw database rewrite could mis-attribute tenant visibility without breaking chain verification (the authoritative org is still hash-bound in the commitment). Supervised fix: cross-check the columns against the hash-committed values.
T8 evidence integrity and tamper-evidence

engagement ENG_01M3X425XKMGQPRS5PCYMGQPRS

Banked · live on /security
v1.7

Authorization Depth

live on /security
Certifies
An authorization cannot be stretched past its expiry, replayed, used after revocation, or widened beyond its capability, grant or credential scope, proven under adversarial reuse.
Attack
Attack the grant lifecycle: reuse a spent approval, use one past expiry, use one after revocation, widen a grant's scope.
Fixed live
Approvals are single-use via an atomic claim, expiry is revalidated at use time on both the collector and bastion layers, revocation runs the same atomic deny gate, capability scope denies unknown agents and binds grants to tool, parameters and targets, and credentials are type-scoped with expiring just-in-time leases. A clean exam; the core invariants were already pinned.
Honest debt
The bastion replay nonce is in-memory (a restart inside the time window reopens a narrow replay window); no standalone grant-revoke primitive yet (mitigated by short lifetimes).
T-AUTH authorization lifetime, single-use, least privilege

engagement ENG_01M3X4VXWXPVCBZF1PVVPVCBZF

Banked · live on /security
v1.8

Resource & Abuse Bounds

live on /security
Certifies
A compromised or runaway caller cannot exhaust money, compute (concurrency, rate, time, output) or queues, the bounds are durable, and every recurring loop carries failure-accounting, backoff and retirement.
Attack
Attack with volume: hammer paid APIs, run unbounded commands, flood queues, spin loops.
Fixed live
Compute is bounded by per-org and per-route rate limiters, an agent loop cap, connector timeouts and size caps. Three missing bounds found and fixed: unbounded paid-API spend (now propose-first), unbounded remote-command time and output (a timeout plus a one-megabyte cap), and an uncapped outbound queue (now depth-limited). Completes the first ladder.
Honest debt
No real per-org spend ceiling yet (propose-first is the interim); the outbound queue is in-memory (the depth cap bounds the live process; persist for cross-restart durability).
T10 bounded resource consumption

engagement ENG_01M3X5EAMEKZYA6YZX53KZYA6Y

Banked · live on /security

honest by default

Honest by default.

A trust claim that hides its gaps is marketing. Here is the carried debt, in one place.

  • Build-provenance observability: most components cannot yet report their running git commit. The fleet agent can. The remediation is specified and is supervised build-pipeline work.
  • A real per-org spend ceiling: paid tools are gated propose-first as an interim; a true cost-budget gate is not built yet.
  • DNS-rebinding egress: literal addresses and cloud-metadata hostnames are blocked; resolve-then-check is not in place yet.
  • In-memory durability: a few replay sets and queues are process-local, so a restart inside a short window can reopen a narrow gap.
  • Stated non-goals: we do not claim universal injection immunity (we certify the boundary is outside the model, not that the model cannot be corrupted), and hostile third-party plugin isolation is a designed, deferred architectural bar (v2.0), not a hidden gap.

not claimed

Not claimed.

What this ladder does not claim, stated up front.

  • Hostile third-party plugin runtime isolation (v2.0, designed, a post-launch stream).
  • Full human-terminal per-command mediation (out of scope).
  • Network-layer denial of service and edge rate limiting (an infrastructure concern, not a bar).
  • Signatures prove artifact provenance and statement integrity, never benign behaviour or the truth of an external effect.

recompute it yourself

Recompute it yourself.

You do not have to take our word for any of this.

  1. 01The published scoreboard on /security is a signed projection: a script recomputes every evidence receipt and refuses to publish on a mismatch, then signs the whole file with a key whose public half is committed to the repository. A --check mode re-verifies both on every build and fails closed.
  2. 02Each bar is a governed engagement whose findings moved from candidate to confirmed to resolved, each transition witnessed. The scoreboard cannot show a finding the store does not hold.
  3. 03Each certified invariant has a continuous-integration test that fails against the pre-fix code and passes after, so ongoing development cannot silently un-bank a passed bar.

ready when you are

Nine bars banked. Nothing here asks for your trust.

Every attack, every fix and every proof on this page is on the public record. Check the evidence yourself before you take our word for any of it.