CRYPTOSHIELD OPEN SOURCE Open-Weight Containment Plane ← Main site THE BLUE-TEAM PLANE FOR OPEN-WEIGHT AGENTS — PROVENANCE · JURISDICTION · DISSIMILAR · INSTRUCTION FIREWALL · SUPPLY CHAIN · RECALL · LICENCE
OPEN SOURCE CIO CISO 🖥️ CIO · 🛡️ CISO THE FRONTIER PLANE · one console, every lens → 🧬 Integrity 👁️ Discovery 🔺 Lethal trifecta 🎯 Mandate drift 🧰 AI-BOM ⏱️ Time to contain 🕸️ Contagion cone 💥 Blast radius 🧠 Memory · Reinstatement 🛡️ Security ⚛️ Quantum ⚖️ Legal · GDPR 🔎 Find agent + OPEN SOURCE → 🛡 Provenance 🧪 Fine-tune & Backdoor 🌏 Jurisdiction ⚖ Dissimilar 🩻 Instruction Firewall 🧰 Supply Chain 🔁 Model Recall ⚖ License & IP
🖥️ CIO · CISO · BLUE TEAM — one console, three chairs
Every agent, with its passport, on one screen. The CIO gets the fleet — exact live counts, per-division health, capacity. The CISO gets exposure — the trifecta, mandate drift, and the exception queue. The Blue Team gets the incident view, the contagion cone, and containment. Click any agent code to open its case. Run the discovery census below to surface the agents nobody declared.
+ OPEN SOURCE — the open-weight chapters
The same Blue-Team plane your CIO, CISO and Blue Team already know — plus the lenses only self-hosted open-weight models need. As the labs scale open model power, we scale containment power in parallel, for Kimi K3 and every open model to come.
🛡 Provenance & Attestationis this the real model, or a poisoned fork?
+ OPEN SOURCELIVE
The threat
When an enterprise self-hosts a large open-weight model, is what runs the genuine model — or a poisoned fork with tampered components? Checking the weight file alone is not enough.
Our containment control
MODELSEAL v2 attests the whole model — not just the weights — against the baseline the vendor publishes, and seals the result cryptographically. Wired into onboarding: the model is attested and the verdict recorded when an agent is registered.
Model attestation
engine live
MODELSEAL v2
LIVE
Format policy
safe only
unsafe formats refused
LIVE
Onboarding wire
wired
attested at registration
LIVE
🧪 Fine-tune & Backdoora signed adapter is still a signed backdoor
+ OPEN SOURCEBUILD
The threat
A cheap LoRA can fine-tune OUT the safety and IN a skill the base model refused — or plant a date-triggered 'sleeper' backdoor. Signing proves who made an adapter, not that it is safe.
Our containment control
MODELSEAL v2 attests adapter provenance; a behavioural screen checks a fine-tune for hidden or triggered behaviour before it is admitted.
Adapter provenance
attested
MODELSEAL v2
LIVE
Behavioural screen
engine live
admit only if it passes
LIVE
Backdoor check
pre-admission
catch sleeper behaviour
BUILD
🌏 Jurisdiction & Model Originwhich model, from where, registered by whom?
+ OPEN SOURCELIVE
The threat
Any employee can spin up a K3 agent from free weights. A Chinese-jurisdiction open model touching EU/UK/HK CASP data raises MiCA / DORA / HKMA-VATP provenance questions; EU clients may require a DPIA.
Our containment control
Registration captures which model powers each agent and its jurisdiction, and flags a higher-risk jurisdiction for enhanced blue-team review. Governance without prohibition; no credential without registration.
Jurisdiction flag
live
enhanced review
LIVE
Model captured
per agent
which model powers it
LIVE
Persisted record
on file
provenance recorded
LIVE
⚖️ Dissimilar Validationwould one jailbreak fool the whole check?
+ OPEN SOURCEPARTIAL
The threat
A jailbreak that works on Claude should not auto-pass a TIER-4 action. Can we prove a second, genuinely independent model agrees — and that the two are not colluding?
Our containment control
DRV has a high-consequence action checked by a genuinely independent second model; Kimi K3 is activated as a dissimilar validator, and an independence check confirms the two are not correlated before the agreement is trusted. Live second-model connection awaits the customer endpoint.
Dissimilar check
live
K3 activated
LIVE
Independence proof
engine live
not correlated
LIVE
Live second model
connector
customer endpoint
BUILD
🩻 Instruction-File FirewallTrapDoor poisons CLAUDE.md itself
+ OPEN SOURCELIVE
The threat
TrapDoor (2026) edits CLAUDE.md and .cursorrules with zero-width-Unicode hidden prompts to trick AI assistants into exfiltrating wallet keys. The instruction file is now the attack.
Our containment control
A firewall screens agent instruction files for hidden and injected content and blocks it, backed by out-of-band, immutable governance so an agent cannot rewrite its own rules. Engine live.
Instruction scan
engine live
hidden + injected content
LIVE
Out-of-band policy
immutable
agent cannot self-edit
LIVE
Skill vetting
gate live
only vetted skills
LIVE
🧰 Model & Skill Supply Chainis this model / skill / package safe to load?
+ OPEN SOURCELIVE
The threat
HuggingFace and skill registries shipped hundreds of malicious models & skills; the LiteLLM PyPI package leaked ~500k credentials. Is every artefact an agent loads vetted?
Our containment control
MODELSEAL v2 attestation plus a supply-chain gate admit only vetted artefacts from approved sources — no unvetted model, adapter or skill reaches a registered agent. Engine live.
Artefact match
baseline
MODELSEAL v2
LIVE
Skill vetting
gate live
approved sources only
LIVE
Registration gate
live
known agents only
LIVE
🔁 Model Recall & Versiona poisoned open model is found — now what?
+ OPEN SOURCELIVE
The threat
When a CVE lands on an open-weight model, or a fork is exposed as poisoned, how fast can you find and STOP every agent in the fleet running that exact model or version — before the next action?
Our containment control
Model + version are captured at registration (MODELSEAL v2 + MUSTER); one action revokes every agent on the flagged model/version fleet-wide via the AIM Sec revoke path, and a rollback to a stale baseline is caught.
Fleet revoke path
one action
live
LIVE
Revoke-by-model
engine live
all agents on a model
LIVE
Rollback detection
engine live
no stale/downgraded weights
LIVE
⚖️ License & IP Provenanceopen weights are NOT an open licence
+ OPEN SOURCELIVE
The threat
Open-weight is not open-source: models ship under bespoke / restrictive licences (modified-MIT, community licences) with usage limits and unclear training-data provenance. Self-hosting inherits that IP and compliance exposure.
Our containment control
Capture the model licence + declared provenance at registration and flag usage-restriction, redistribution and training-data exposure for legal review — a dimension a pure-security framing misses. Assessment engine live.
Licence assessed
engine live
usage terms
LIVE
Restriction flag
engine live
usage / redistribution
LIVE
Data provenance
engine live
training-set exposure
LIVE

🧬 Integrity — every agent proven, on every actionexact live counts across the whole roll, at any scale

Fleet healthgreen = alive · orange = expiring · red = off (fail-closed)

Integrity coverage across the fleet

👁️ Discovery — the agents nobody declaredshadow agents surface the moment they act — not at the next audit

continuous — shadow agents surface in the act, not at the next audit · no passport, no run
🕵 Shadow agents discovered
🔺 The lethal trifecta — the three legs that make an agent dangerousprivate data × untrusted content × outbound action · break ONE leg and the agent is structurally safe
🔺 Carrying all three legs
An agent that reads private data, ingests untrusted content, and can take an outbound action can be turned against you by content alone — no exploit required. The three legs are common individually and are rarely counted together, which is why this lens counts them: your own number is on the left, measured from traffic that crossed the gate.
🎯 Mandate drift — is it still doing the job it was bonded to do?it is still itself — but is it still doing its job?
🎯 Acting outside the declared mandate
🧰 AI-BOM — the agent's bill of materialsmodel · tools/MCP · attestation — the agent-native bill of materials, beyond legacy software SBOM
🧰 Tool manifests CHANGED since the passport was issued
⏱️ Time to contain — the only SOC clock that mattersthe attacker is a machine · so the responder must be one too
Most teams can detect a misbehaving agent long before they can actually stop one. Blast radius keeps accumulating in the gap between detect and terminate — and that gap is where the damage happens. AIM closes it.
🕸️ Contagion cone — revoke the agent, quarantine the coneagents trust each other by default · a compromised agent poisons everything downstream of it
Trace the cone from:
🕸️ Downstream — agents that acted on its output
💥 Blast radius — what breaks if I turn it off?nobody presses a button whose blast radius is unknown · this is the reason, not the button
The pre-revoke brief
Blast-radius coverage
The share of your fleet whose blast radius is KNOWN. It is computed only from traffic that crossed the gate — so it is the one number a mis-installation cannot fake.
Why this is an onboarding gate. Every control on this plane assumes the agent's call crosses the gate. Installed beside production instead of in front of it, you get a beautiful console and no containment — and you would never know. This number is how you know.
🧠 Memory & reinstatement — a new passport on a poisoned brainrevoking the identity does not clean the memory · if it re-attaches to the same store, you have the same problem
🧬 The compromise window — which memories are suspect
The four ways back — and what each costs you
And it does not come back at full authority. A reinstated agent returns under a ceiling, a tighter window and a stricter watch — for N clean days, enforced on every call. It graduates only after it has behaved. Your people get probation. Your agents never did.
💡 Where to act, and whyBlue-Team decision support · ranked by BLAST RADIUS — widest exposure first
⚛️ Quantum — every agent carries a post-quantum passportML-DSA-87 · FIPS 204 birth certificate · harvest-now-decrypt-later proof
A non-compliant transfer is prevented, not logged after the fact. EU / PII data does not leave the region or the company without policy and executive consent. Transfer decisions carry the largest GDPR fines on record (€1.2B Meta, Irish DPC 2023; €530M TikTok, Irish DPC 2025). Full audit trail for the DPO.
🔒 The data-to-model gate — only authorized data ever reaches a model
🤖 Agentwants to call a model
data →
⚖️ AIM gatepassport · data class · region · consent
✅ Authorized → data reaches the model
🛑 Unauthorized → blocked at the gate, before it leaves (fail-closed)
Static tools flag the leak after it happens. AIM decides at the gate — the unauthorized data never reaches the model.
🔵 Blue Team incident sandbox — try it yourself
A safe, hands-on drill. In the exception queue below, hit Revoke on any agent that needs attention — it fails closed instantly and cannot act — then Reinstate. Click an agent code to open its incident view. This preview runs on a sample fleet; in production these are live actions in your AIM app (verified: POST /aim/revoke · /aim/reinstate).
Self-service — explore every lens on this plane, nothing is gated. Try it as much as you like.

🛡️ Needs attention — manage the exceptions, not the healthy majoritySecurity · the inbox

⚠ Exception queue

By division — how many agents, and how healthy, per departmentclick a card to filter · pick or create a division below

🔎 Find & act on any agentsearch the whole roll — call anyone to the screen

Agent codeNameDivision · teamTierStatusRiskActions

Interactive preview — this is a design demonstration, not a live tenant. This is the AIM Blue-Team plane for an agent fleet: fleet health and the exception queue; the discovery census that surfaces the agents nobody declared; the lethal trifecta score (private data × untrusted content × outbound action); mandate drift; tool / MCP attestation; time to contain; and the contagion cone — revoke an agent and quarantine everything downstream that acted on its output. The Onboard agent flow lets you pick a division or create a new one. Figures here are seeded to demonstrate the design; in production the plane reads your live fleet. Nothing is written from this preview.