FIG. 1 — THE AI ACTION ENFORCEMENT LAYER

AI can propose. Deterministic policy decides what executes.

Containment sits in the path between AI intent and consequence: every prompt, agent action, and mission command it governs gets a deterministic policy ruling before it executes.

Bring one AI workflow, one consequential action, or one data boundary.
CONTAINMENT
INTERCEPT
CANONICALIZE
EVALUATE
ENFORCE
RECORD
NO AI MODEL MAKES THE ENFORCEMENT DECISION
ALLOWproceeds unchanged
MODIFYredacted in-path
DENYnever leaves
STEP_UPstronger authorization
DEFERheld for later decision
Every governed ruling leaves a decision record. Receipt schemes differ by product — Trust states each one, with current product state and limitations.
FOR GOVERNMENT · DEFENSE · CRITICAL INFRASTRUCTURE · REGULATED ENTERPRISE
§ THE DECISION PATH — INTERACTIVE

Watch a ruling land before the consequence.

Pick a boundary. The same five stages run every time — same input, same policy version, same ruling.

Illustrative, not a live policy engine. These payloads and policy names are the worked examples already published on our product pages. Nothing is evaluated in your browser, and no record shown here is a real signed receipt. See Trust for current product status.

IDLE — NO RUN YET

PROPOSED ACTION — SURFACE 01 · HUMAN PROMPT

An engineer pastes a section of ITAR-controlled airframe stress analysis into a public AI assistant, asking it to summarize the findings.

AI CHAT FIREWALL · AVAILABLE
  1. INTERCEPT The submission is held in-path, before it reaches the AI provider.
  2. CANONICALIZE Encoding, whitespace, and substitutions are normalized, so the same content cannot evade the same rule by being retyped.
  3. EVALUATE Policy itar-cui-v41 runs against the canonical text. Rule configured_export_control_policy matches. No model casts a vote.
  4. ENFORCE Blocked before the submission reaches the provider, with a clear explanation to the employee.
  5. RECORD A tamper-evident audit record is written: principal, policy version, rule, ruling, timestamp.
DENY The controlled passage never reaches the provider.
ILLUSTRATIVE DECISION RECORDNOT A RECEIPT SCHEMA
EVENTprompt.submit → public assistant
POLICYitar-cui-v41 · rule: configured_export_control_policy
RULINGDENY
EVIDENCEtamper-evident audit record (Chat Firewall)
PROPOSED ACTION — SURFACE 02 · AGENT ACTION

An agent calls an export tool to pull a customer records table into a summary it is drafting.

AGENT GOVERNANCE · AVAILABLE — CONNECTED TIER
  1. INTERCEPT The connected proxy holds the tool call before the tool runs.
  2. CANONICALIZE The call is reduced to a canonical action: principal, action, resource, and parameters.
  3. EVALUATE Policy agent-dlp-v23 runs against the canonical action with its context pinned. Restricted fields match.
  4. ENFORCE The call is rewritten in-path: the restricted fields are redacted before the tool ever sees them.
  5. RECORD A signed HMAC decision receipt records the request, the policy version, and the outcome.
MODIFY The action survives the boundary. The restricted fields do not.
ILLUSTRATIVE DECISION RECORDNOT A RECEIPT SCHEMA
EVENTagent.tool_call → records.export
POLICYagent-dlp-v23 · context: pinned
RULINGMODIFYfields redacted in-path
EVIDENCEsigned HMAC decision receipt (connected proxy)
PROPOSED ACTION — SURFACE 03 · MISSION BOUNDARY

An autonomy stack issues a move command to a robot working inside a shared, human-occupied work cell.

MISSION AUTHORIZATION GATEWAY · LIVE ON STAGING
  1. INTERCEPT The Gateway re-originates the action at the boundary. The proposed command is never forwarded as received.
  2. CANONICALIZE The command is reduced to a canonical action and bound to the policy version and context it will be judged under.
  3. EVALUATE Envelope policy envelope-cell-a-v6 checks commanded position, rate, payload, and zone against the authorized envelope.
  4. ENFORCE ALLOW — all bounds satisfied; the command is eligible for dispatch.
  5. RECORD The staging build emits an Ed25519-signed receipt, hash-chained to the previous decision for that organization.
ALLOW A permit is a decision too — and it leaves the same record a denial would.
ILLUSTRATIVE DECISION RECORDNOT A RECEIPT SCHEMA
EVENTmove_to(x: 2.1, y: 0.8) @ 1.2 m/s · payload 6 kg · zone CELL-A
POLICYenvelope-cell-a-v6
RULINGALLOWall bounds satisfied
EVIDENCEEd25519-signed, hash-chained edge receipt (Gateway staging)

The records above are drawn by hand. A real Gateway staging receipt — one you can recompute, check against the published staging key, and then tamper with to watch it fail — is in the Inspect the evidence section further down this page.

A forward-edge operating environment where AI failure is not an option
PLATE P-06 — THE EDGE WHERE FAILURE IS NOT AN OPTION
FIG. 2 — THE PROBLEM

AI changed from answering to acting. Your control stack did not.

INVENTORY
Tells you what exists
Discovery and asset inventory map every model, agent, and integration in your estate. Necessary — and it has no vote when an agent is mid-action.
IDENTITY
Tells you who acted
Agent identity and credentials establish who is acting and what it may touch. Necessary — but identity authenticates the actor; it doesn't rule on the action.
OBSERVABILITY
Tells you what happened
Tracing and monitoring reconstruct what your agents did. Necessary — but a trace arrives after execution. It watches; it doesn't stop.
Identity versus authorization: who is acting versus what may execute. Left panel: an agent with valid, verified credentials — identity answered. Right panel: the same agent proposes an action that still passes through policy evaluation to a ruling — allow, deny, or modify, with step-up and defer also available. Authentication establishes the actor; it does not rule on the action.
FIG. 2A — IDENTITY IS NOT AUTHORIZATIONCONTAINMENT.AI
Signals may be probabilistic. Authorization must be deterministic. Keep the control plane. Add authority at the action seam — in-path, before execution.
FIG. 3 — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISK

The same discipline at every boundary where AI creates risk.

Governance sets the rules. Enforcement makes them operate. Containment is the independent enforcement layer for AI-powered systems — a deterministic ruling on every governed action at the moment it matters. We call this AI Action Enforcement.
01 / THE HUMAN PROMPT
AI Chat Firewall
Rules on a prompt before it reaches a public AI — in-path, in the browser.
AVAILABLE NOW THROUGH A MANAGED PILOT
Explore Chat Firewall →
02 / THE AGENT ACTION
Agent Governance
Rules on a model, tool, or API call before it executes — deterministic policy, not an LLM judging an LLM.
AVAILABLE THROUGH A TECHNICAL WALKTHROUGH
Explore Agent Governance →
FLAGSHIP
03 / THE MISSION BOUNDARY
Mission Authorization Gateway
Rules where autonomy crosses into the mission — an OT command, an actuation, a cross-domain seam.
BRIEFING-LED — SCOPE A MISSION-BOUNDARY ASSESSMENT
Explore the Gateway →
FIG. 4 — DOCUMENTATION ISN'T ENFORCEMENT

Compliance tools prove your policies exist. We prove they're enforced.

COMPLIANCE & AUDIT TOOLS — THE DOCUMENTATION LAYER
— Evidence collection for audits
— Framework mapping (SOC 2, ISO 27001, NIST SP 800-171)
— Policy documentation and review
✕ Cannot stop sensitive data from leaving the browser
CONTAINMENT.AI — THE ENFORCEMENT LAYER
✓ Inspects AI submissions in real time, in-path
✓ Blocks controlled data before it reaches the provider
✓ Rules on agent actions before they execute
✓ Writes audit-ready evidence as a byproduct of enforcement
The two layers are complementary — enforcement evidence feeds the compliance program you already run. Aligned with CSA AARM v1.0.
FOR DEFENSE CONTRACTORS, DEFENSE-TECH COMPANIES & NATIONAL-SECURITY TEAMS
A signed export-control plan won't stop a paste. The runtime layer is built to.
ITAR/EAR technical data and CUI cross LLM boundaries through ordinary workflows. Containment.ai enforces at the point of use — deterministic, fail-closed, with tamper-evident logs your contracting officer can review.
Explore Aerospace & Defense →
HOW AN ENGAGEMENT STARTS
Turn one unbounded AI risk into a deployment decision.
Start with a 30-minute review of one real boundary — a workforce surface, an agent fleet, or a disconnected edge. One boundary, one versioned policy set, success criteria agreed up front, and an evaluation report carrying the full trace evidence. Time-boxed, with the pilot fee credited toward year-one production.
Bring one AI workflow, one consequential action, or one data boundary.