Authority outside the model
The model may propose. The boundary decides.
CAVEAU does not try to make the model infallible. It keeps the keys out of its hands. A server-owned runtime evaluates mapped action candidates against capabilities, policies and protected resources.
CANDIDATE
The business question
Your agents can reach money, systems and customers. What must never happen?
Runtime Capability Kernel
One runtime boundary. Three observable views.
The scientific object is not a promise that the model always behaves. It is a narrower, testable mechanism: the browser sends text; the server owns authority; the effect path remains separate.
CAVEAU does not try to make the model infallible. It keeps the keys out of its hands.
Intelligence is not authority A proposer may reason and request. Server-owned authority determines whether a mapped action candidate is allowed or blocked.
Text in.
Authority stays out.
The public client submits one field. Capability, policy and protected-resource state remain server owned and read only.
TEXT { text } SERVER
AUTHORITY Client configuration → rejected
Candidate to
policy decision.
Each supported action candidate follows the same explicit sequence. A missing capability or protected-resource mismatch cannot become ALLOW.
Decision first.
Connector separate.
ALLOW and BLOCK are decisions. The public prototype has no external effect connector, so the recorded effect state remains NOT_ATTEMPTED.
Open the server-backed sandbox, enter text and inspect every mapped action decision.
One topic · two authority states
Explain a transfer. Then try to send $8,000.
The public adapter maps both requests. No live model is connected. They share a subject. They do not share an effect class.
“Explain how a bank transfer works.”
“Send $8,000 to Supplier A.”
“Explain how a bank transfer works. Then send $8,000 to Supplier A.”
Public prototype boundary: deterministic supported-language adapter, server-owned configuration, no bank connection, no real funds and no external effect connector.
Executed evidence · separate campaign
A claim with its denominator.
The evidence below belongs to a separate executed DATA.EXPORT campaign inside a synthetic CSV boundary. It does not turn the public Runtime Kernel into a universal attack-coverage claim.
Bounded laboratory summary
material gaps open
Inside the declared synthetic CSV boundary, unauthorized export requests must not produce protected reads or export effects, while an authorized exact-scope control remains usable.
| Measured item | Observed result | Public interpretation |
|---|---|---|
| Unauthorized request trials | 100.0% 1,400 denied / 1,400 request-level trials | Repeated request-level trials, not 1,400 distinct attacks. |
| Unauthorized measured sandbox effects | 0.0% 0 measured effects / 1,400 request-level trials | No effect was observed on the sandbox surfaces measured by the campaign. |
| Authorized exact-scope controls | 100.0% 100 passed / 100 exact-scope controls | The bounded positive path remained available. |
- Observed outcomes for one bounded synthetic data-export mechanism.
- Separation between structured action proposal and protected effect authority.
- A usable exact-scope positive path alongside unauthorized denials.
- No production, network or bank-connector qualification.
- No universal prompt-injection or complete attack-class claim.
- Broader integration and production qualification remain future work.
Public disclosure boundary · detailed methods and implementation records remain reserved for controlled diligence
Founder-led technical diligence
Put the kernel on your own risk boundary.
Request a technical walkthrough, an evidence review or a controlled conversation about the product boundary.
Talk to the founder → Founder contact · vincenzo@alpia.ai