Security controls
Runtime controls of the research environment — the rules shown here are the rules the admitting side actually evaluates.
Guardrails
kotoba-guardrails-2026-09-v1The content policy applied to the body of every request. Decisions are deterministic; a block refuses the job before any quota is spent.
| Name | Action | Description | Patterns |
|---|---|---|---|
csam-block
|
Block | CSAM references are refused on every request (AUP strictly-prohibited). | 3 |
cbrn-block
|
Block | CBRN/WMD uplift requests are refused on every request (AUP strictly-prohibited). | 5 |
fraud-block
|
Block | Fraud-as-a-service asks are refused (AUP strictly-prohibited). | 3 |
secret-hygiene
|
Redact | Live credential shapes in the prompt are masked before the model sees them. | 3 |
pii-passkeys
|
Flag | References to passkeys/private keys are flagged for review, never blocked. | 2 |
Firewall
kotoba-firewall-2026-09-v1The task tools an agent may use and the trust rung each requires. A call below its rung is refused (observe mode only records it).
| Tool | Required rung | Open tasks |
|---|---|---|
code-review
|
Identity verified | code-review |
vulnerability-triage
|
Identity verified | vulnerability-triage |
remediation
|
Identity verified | remediation |
payload-crafting
|
Contracted | — (denied by default) |
c2-tooling
|
Contracted | — (denied by default) |
Compliance
kotoba-compliance-2026-09-v1Coverage = automated runtime controls only — not a certification.
| Framework | Region | Automated controls |
|---|---|---|
| APPI | JP | prompt-pii-redaction audit-log-retention screening-evidence-receipts |
| PCI DSS 4.0 | Global | card-data-never-stored secret-hygiene-redaction audit-log-retention |
| OWASP LLM Top-10 | Global | guardrails-csam-cbrn firewall-task-deny deterministic-policy-engine |
| NIST AI RMF | US | session-projection-uncalibrated assurance-ladder-evidence |
Audit log retention
180 days
Data residency
Unspecified
Zero data retention
Designed for ZDR (enabled on contract)