G‑14 Security

Security starts at the action gate.

Models, agents, tools, and sensors can be wrong, manipulated, or over-authorized. The G‑14 security model places an external control point between a consequential proposal and its effect, then preserves an attributable receipt for review.

Security control path Explicit decision
01

Bind the proposal

Identify the actor, target, operation, scope, policy context, and expected consequence before reliance.

02

Check authority and evidence

Evaluate the configured policy, authority, freshness, custody, state, and required supporting evidence.

03

Hold, block, or release

Return an explicit decision before the connected effect or communication channel proceeds.

04

Preserve the receipt

Bind proposal, decision, evidence, outcome, timing, and verifier references for later review.

Threat modelThreats enter through input, authority, state, and evidence.
Read the threat model
UNTRUSTED INPUTHostile or ambiguous

Prompts, tool output, sensor data, retrieved content, and agent messages can be manipulated, incomplete, or wrong.

EXCESSIVE AGENCYAuthority too broad

A capable model can still request an action outside the actor, resource, scope, or consequence it is permitted to control.

STATE MISMATCHStale or conflicting

A once-valid instruction can become unsafe when identity, policy, environment, evidence, or operating state changes.

EVIDENCE FAILUREOutcome not attributable

Logs alone may not prove which proposal, policy, evidence, decision, signer, and effect belonged to the same run.

Control response

The gate checks before an effect can run.

These are the documented properties of the G‑14 control contract. Whether they are correctly configured and operated must be verified in each target environment.

Typed proposal boundary

The published model requires consequential actions and conclusions to arrive as explicit proposals before they cross the boundary.

Inspectable request
Policy and evidence gate

Configured authority, state, evidence, and release conditions determine the decision—not model confidence alone.

Deterministic control point
Fail-closed state handling

The control contract treats missing authority, missing required evidence, invalid packets, and expired conditions as hold or rejection paths.

No silent fallback
Receipt and replay boundary

The evidence model binds request, decision, signer, outcome, and verifier references so later review is not limited to a dashboard.

Attributable record
Assurance boundaryPublished evidence and deployment assurance are different things.
Verify the public artifact
PUBLIC MODELDocumented

The threat model, authority boundary, fail-closed behavior, evidence model, and deployment boundary are published for inspection.

PUBLIC PROOFAMR v0

The downloadable pack demonstrates signed positive packets and named rejection cases through one offline verifier path.

PRIVATE REVIEWEnvironment-specific

Identity, keys, networks, connectors, data custody, retention, and operating procedures require review in the target deployment.

ASSURANCE LIMITNo certification claim

These materials are not a third-party audit opinion, regulatory approval, production attestation, or claim of standards certification.

The current public artifact was generated April 25, 2026. Its verifier path records 225 checks, zero failed checks, and a valid signature for the captured positive packet.

Standards references

Current frameworks used as review lenses.

These references help organize control and evidence discussions. Their inclusion does not assert certification, conformance, or a completed independent assessment.

NIST AI RMF 1.0Reference lens for Govern, Map, Measure, and Manage. See NIST for current revision status.Official source →
NIST CSF 2.0Reference lens for Govern, Identify, Protect, Detect, Respond, and Recover across the deployment boundary.Official source →
ISO/IEC 42001:2023Reference lens for AI management-system risk controls, oversight, evidence, and continual improvement.Official source →
ISO/IEC 27001:2022Reference lens for information-security management, risk treatment, access, change, incident, and audit controls.Official source →

Security review

Bring the real deployment boundary.

A useful review identifies the actors, data, policy authority, keys, connected effects, network boundary, recovery path, and evidence obligations for one consequential workflow. Contact security@g14.ai.

Request boundary review