Blog
Notes on securing AI agents with deterministic policy: signed manifests, enforcement, and tamper-evident audit.
4 min read
A model can be persuaded. A signed policy cannot.
Why prompt-level rules are not a security boundary for AI agents, and what a deterministic, signed policy changes about the problem.
securitypolicyprompt-injection
3 min read
What a hash-chained audit log actually proves
Tamper-evident is not tamper-proof. A precise look at the guarantees of AgentLaw's audit chain — and at the claims it deliberately does not make.
auditintegrityspec