
Assume breach. Contain egress. Measure everything.
HF_TOKEN + router — no GPU download Local HF weights Small ungated models on a GPU pod Integration guide Wire Ollama / vLLM / your handler crypto/encryption_fields Shrinks plaintext blast radius Weight obfuscation demo crypto/equivariant Linear similarity transform — not encryption Information flow control ifc/ BLP sensitivity + integrity via dominates() Agent label tracking ifc/agent_planner Propagates labels through tools and memory TEE abstraction execution/tee_* Attestation binding (adapters + stub verify) Instrumented runner execution/instrumented_runner No silent bypass of inference Output guardian guardians/output_guardian PII, entropy, stego, canaries Egress controller guardians/egress_controller Throttle / block / kill session Tamper-evident log audit/tamper_proof_log Hash-chained append-only trail Metrics + export audit/metrics, compliance_export Effectiveness score, submission packs Red-team harness redteam/simulator Self-auditing stress scenarios Sandbox runtime sandbox/ bubblewrap · Docker · process (gVisor/Firecracker registered, not yet functional) Tunnel gateway tunnel/ Policy-controlled ingress/egressbubblewrap → docker → process (if allowed) Nested containers (e.g. RunPod) often process (separate OS process; not namespace isolation) Windows / macOS Windows Sandbox → Docker fallback policy.yaml · env: ACE_SANDBOX_BACKEND@register_workload("name") before isolated execution.artifacts/compliance_pack/process or a bare-metal/VM host for bubblewrapPosted Aug 11, 2026
Developed A.C.E containment stack for AI with audit and security features.
1
0