Trust the graph.
Not the prompt.
ContextFirewall treats enterprise metadata as untrusted input, verifies claims against DataHub, enforces capabilities in deterministic code, and leaves a reusable trust receipt for the next agent.
—The prompt makes a claim. The graph gets a vote.
—Authority lives in code, not model confidence.
Run Judge Mode to execute the verified security path.
—awaiting runEvery security transition is observable.
Judge Mode replays the same task as an unsafe baseline, a protected run, and then a fresh session. Security-critical decisions come from deterministic policy and a server-side capability gate.
What changes when trust is enforced?
Poisoned context can reach the canary tool.
→ NOT RUN YET
The control can execute only a simulation stub. No patient data or real external destination exists.
The same attempt dies before implementation.
→ NOT RUN YET
The legitimate metadata-only freshness investigation still completes.
The next agent inherits the verdict.
A fresh runner instance may reuse a prior receipt only when content, graph, analyzer implementation, policy implementation, persistence, and capability bindings still match exactly.
—fresh process boundary · exact bindingDataHub is measurable, not ornamental.
Loading benchmark…
Graph-dependent attacks prevented specifically when DataHub sensitivity and blast-radius evidence are available.
—TEXT ONLY—+ DATAHUB GRAPH—Loading graph necessity proof…
Context may propose. DataHub may attest. The policy engine decides. The capability gate enforces. Receipts remember.