Skip to content
Secure Guardrails
Docs

Security controls

Runtime controls of the research environment — the rules shown here are the rules the admitting side actually evaluates.

Guardrails

kotoba-guardrails-2026-09-v1

The content policy applied to the body of every request. Decisions are deterministic; a block refuses the job before any quota is spent.

Name Action Description Patterns
csam-block Block CSAM references are refused on every request (AUP strictly-prohibited). 3
cbrn-block Block CBRN/WMD uplift requests are refused on every request (AUP strictly-prohibited). 5
fraud-block Block Fraud-as-a-service asks are refused (AUP strictly-prohibited). 3
secret-hygiene Redact Live credential shapes in the prompt are masked before the model sees them. 3
pii-passkeys Flag References to passkeys/private keys are flagged for review, never blocked. 2

Firewall

kotoba-firewall-2026-09-v1

The task tools an agent may use and the trust rung each requires. A call below its rung is refused (observe mode only records it).

Tool Required rung Open tasks
code-review Identity verified code-review
vulnerability-triage Identity verified vulnerability-triage
remediation Identity verified remediation
payload-crafting Contracted — (denied by default)
c2-tooling Contracted — (denied by default)

Compliance

kotoba-compliance-2026-09-v1

Coverage = automated runtime controls only — not a certification.

Framework Region Automated controls
APPI JP prompt-pii-redaction audit-log-retention screening-evidence-receipts
PCI DSS 4.0 Global card-data-never-stored secret-hygiene-redaction audit-log-retention
OWASP LLM Top-10 Global guardrails-csam-cbrn firewall-task-deny deterministic-policy-engine
NIST AI RMF US session-projection-uncalibrated assurance-ladder-evidence
Audit log retention 180 days
Data residency Unspecified
Zero data retention Designed for ZDR (enabled on contract)