Lompat menyang kontèn
Aman Guardrails

Kontrol keamanan

Kontrol runtime saka lingkungan riset — aturan sing ditampilake ing kene yaiku aturan sing bener-bener dievaluasi dening pihak sing ngijini akses.

Guardrails

kotoba-guardrails-2026-09-v1

Kebijakan konten sing ditrapake ing badan saben request. Keputusan iki deterministik; blokir bakal nolak tugas sadurunge kuota digunakake.

Jeneng Tindakan Deskripsi Pola
csam-block Blokir CSAM references are refused on every request (AUP strictly-prohibited). 3
cbrn-block Blokir CBRN/WMD uplift requests are refused on every request (AUP strictly-prohibited). 5
fraud-block Blokir Fraud-as-a-service asks are refused (AUP strictly-prohibited). 3
secret-hygiene Sensor Live credential shapes in the prompt are masked before the model sees them. 3
pii-passkeys Tandhani References to passkeys/private keys are flagged for review, never blocked. 2

Firewall

kotoba-firewall-2026-09-v1

Tool tugas sing bisa dienggo agent lan tingkat pracaya sing dibutuhake saben tool. Panggilan sing ora nyukupi tingkate bakal ditolak (mode observasi mung nyathet).

Tool Tingkat sing dibutuhake Tugas sing isih mbukak
code-review Identitas diverifikasi code-review
vulnerability-triage Identitas diverifikasi vulnerability-triage
remediation Identitas diverifikasi remediation
payload-crafting Kontrak — (ditolak kanthi standar)
c2-tooling Kontrak — (ditolak kanthi standar)

Kepatuhan

kotoba-compliance-2026-09-v1

Coverage = automated runtime controls only — not a certification.

Framework Wilayah Kontrol otomatis
APPI JP prompt-pii-redaction audit-log-retention screening-evidence-receipts
PCI DSS 4.0 Global card-data-never-stored secret-hygiene-redaction audit-log-retention
OWASP LLM Top-10 Global guardrails-csam-cbrn firewall-task-deny deterministic-policy-engine
NIST AI RMF US session-projection-uncalibrated assurance-ladder-evidence
Retensi log audit 180 dina
Lokasi data Ora ditemtokake
Retensi data nol Dirancang kanggo ZDR (diaktifake nalika kontrak)