RESOURCES — THE RECORD
Inspect the evidence. Read the limits.
Architecture, current product state, technical artifacts, and postmortems — published for scrutiny.
FORWARDABLE BRIEFS — NO FORM, NO EMAIL REQUIRED
One page each, written to be sent to someone who was not on the call. Print or save as PDF and the site chrome drops out.
BRIEF 01
Reading a decision record
What the record contains, how to verify a real one, and where the claim stops. For a contracting officer.
OPEN →
BRIEF 02
OT deployment & fail-closed behaviour
Where the Gateway sits, what happens on a DENY, and what only your pilot can establish. For an OT engineer.
OPEN →
BRIEF 03
AARM v1.0 alignment
Aligned, not certified: which requirements are satisfied, which is a gap, which is out of scope. For a compliance owner.
OPEN →
START HERE — THE RECORD, IN READING ORDER
01 WHITEPAPER — THE ARGUMENT
→
02 TRUST — THE STATUS
→
03 DOGFOOD — THE PROOF
→
04 POSTMORTEMS — THE FAILURES
FOR YOUR SECURITY TEAM: TRUST + COMPLIANCE · FOR YOUR ENGINEERS: WHITEPAPER + BLOG · FOR YOUR CONTRACTING OFFICER: TRUST + POSTMORTEMS
DOC 01 · THE ARGUMENT
Whitepaper
The full argument for deterministic runtime governance, and the architecture that delivers it.
READ →
DOC 02 · FIELD NOTES · ONGOING
Blog
Engineering notes on canonicalization, policy engines, and governing AI where the network ends.
READ →
DOC 03 · CANONICAL · REVIEWED QUARTERLY
Trust & Security
The canonical statement of our assurance status — what is claimed, what is in progress, what is not.
READ →
DOC 04 · FRAMEWORK MAPPING
Compliance
Framework mapping and current posture across SOC 2, NIST SP 800-171, and the paths in progress.
READ →
DOC 05 · STANDING RECORD
How we run on Containment.ai
Our agent workforce runs under deterministic workflow controls. Action-guard enforcement is currently shadow/observe, and the gap is published.
READ →
DOC 06 · INCIDENT LOG
Postmortems
When something breaks, we publish what happened. A governance vendor that hides failures isn't one.
READ →
DOC 07 · SOLUTION · FRONTIER AGENTS
Frontier Agent Control
Sandboxes constrain where frontier agents run. MAG authorizes what they may make happen — deterministic, pre-execution control at the action seam.
READ →
MISSION BRIEFS & FIELD NOTE — UNGATED, NO FORM
BRIEF 01 · PDF · UNGATED
MAG — Frontier Agent Control
The product brief: deterministic authorization for frontier agents — what exists now, what is tailored per deployment, and the claim boundaries.
DOWNLOAD →
BRIEF 02 · PDF · UNGATED
MAG — Autonomy & Tactical Edge
The product brief for autonomy and tactical-edge missions: pre-execution authorization where the network ends and effects are physical.
DOWNLOAD →
FIELD NOTE · BLOG
Frontier agent control and the July 2026 incidents
What the OpenAI, Hugging Face, and Anthropic disclosures actually show — and where an authorization boundary fits.
READ →
THE EVIDENCE CENTER — ARTIFACT INDEX
The documents above are the argument. These are the artifacts — cryptographic material you can check yourself, in your own browser, without talking to us.
| ARTIFACT | WHAT IT CAN ESTABLISH |
|---|---|
| Gateway receipt integrity package | One isolated page containing the local verifier, staging sample and tamper test, format documentation, and published staging key. It recomputes the receipt hash, verifies the Ed25519 signature against that key, and checks continuity of the supplied chain segment. It does not re-run policy, prove chain completeness beyond the supplied segment, or establish production deployment or authorization. Receipt checks run locally; the verifier makes no outbound data requests and never uploads receipt data. No account. |
| AARM Core self-attestation | Per-requirement conformance record against CSA's AARM v1.0 — including the gaps. The public attestation document is the controlling record. |
| Agent Governance Toolkit comparison | Where Microsoft's Agent Governance Toolkit and an in-path enforcement layer do different jobs — control-plane governance versus a deterministic ruling at the action seam. |
| Enforcement & audit evidence | The canonical assurance record — product-specific decision-record profiles, current availability, limitations, and the milestone status behind every claim on this site. |
RECEIPTS, PER PRODUCT
MISSION AUTHORIZATION GATEWAY · FLAGSHIP
The Gateway staging build emits Ed25519-signed, per-organization hash-chained receipts at the edge seam. The browser verifier checks receipt integrity, the published staging key, and continuity of the supplied segment.
AGENT GOVERNANCE
The connected proxy issues HMAC-signed decision records, verified inside the deployment. Product scope and current status are stated on Trust.
AI CHAT FIREWALL
Every ruling writes an audit-ready, tamper-evident receipt — feeding the compliance program you already run.
The browser verifier and published staging key are Mission Authorization Gateway artifacts. It checks receipt integrity, signer key, and supplied-segment continuity; it does not re-run policy.
SEEN THE RECORD?
Now watch it rule on your workflow.
Request a 30-minute Boundary ReviewBring one AI workflow, one consequential action, or one data boundary.