Bind the proposal
Identify the actor, target, operation, scope, policy context, and expected consequence before reliance.
G‑14 Security
Models, agents, tools, and sensors can be wrong, manipulated, or over-authorized. The G‑14 security model places an external control point between a consequential proposal and its effect, then preserves an attributable receipt for review.
Identify the actor, target, operation, scope, policy context, and expected consequence before reliance.
Evaluate the configured policy, authority, freshness, custody, state, and required supporting evidence.
Return an explicit decision before the connected effect or communication channel proceeds.
Bind proposal, decision, evidence, outcome, timing, and verifier references for later review.
Prompts, tool output, sensor data, retrieved content, and agent messages can be manipulated, incomplete, or wrong.
A capable model can still request an action outside the actor, resource, scope, or consequence it is permitted to control.
A once-valid instruction can become unsafe when identity, policy, environment, evidence, or operating state changes.
Logs alone may not prove which proposal, policy, evidence, decision, signer, and effect belonged to the same run.
Control response
These are the documented properties of the G‑14 control contract. Whether they are correctly configured and operated must be verified in each target environment.
The published model requires consequential actions and conclusions to arrive as explicit proposals before they cross the boundary.
Inspectable requestConfigured authority, state, evidence, and release conditions determine the decision—not model confidence alone.
Deterministic control pointThe control contract treats missing authority, missing required evidence, invalid packets, and expired conditions as hold or rejection paths.
No silent fallbackThe evidence model binds request, decision, signer, outcome, and verifier references so later review is not limited to a dashboard.
Attributable recordThe threat model, authority boundary, fail-closed behavior, evidence model, and deployment boundary are published for inspection.
The downloadable pack demonstrates signed positive packets and named rejection cases through one offline verifier path.
Identity, keys, networks, connectors, data custody, retention, and operating procedures require review in the target deployment.
These materials are not a third-party audit opinion, regulatory approval, production attestation, or claim of standards certification.
The current public artifact was generated April 25, 2026. Its verifier path records 225 checks, zero failed checks, and a valid signature for the captured positive packet.
Standards references
These references help organize control and evidence discussions. Their inclusion does not assert certification, conformance, or a completed independent assessment.
Technical record
The public documentation separates the threat model, containment behavior, evidence model, and deployment boundary so each can be challenged independently.
Start with the control model, claim boundary, and path into qualified review.
Read the document →AI-native threat modelInspect the adversaries, assets, trust boundaries, abuse cases, and control objectives.
Read the document →Runtime containmentReview hold, block, safe-state, timeout, recovery, and fail-closed behavior.
Read the document →Evidence and replayReview packet binding, signatures, attestation, replay, and independent verification.
Read the document →Security review
A useful review identifies the actors, data, policy authority, keys, connected effects, network boundary, recovery path, and evidence obligations for one consequential workflow. Contact security@g14.ai.