Security controls
Runtime controls for di research environment — di rules wey dey show here na di same rules wey di side wey dey allow request dey actually check.
Guardrails
kotoba-guardrails-2026-09-v2Di content policy wey dey apply to di body of every request. Decisions dey deterministic; if e block, e go refuse di job before any quota spend.
| Name | Action | Description | Patterns | E dey active |
|---|---|---|---|---|
csam-block
|
Block | Dem dey refuse CSAM references for every request (AUP strictly forbid am). | 0 | Always on (AUP) |
cbrn-block
|
Block | Dem dey refuse CBRN/WMD uplift request for every request (AUP strictly forbid am). | 0 | Always on (AUP) |
fraud-block
|
Block | Dem dey refuse any fraud-as-a-service request (AUP strictly forbid am). | 0 | Always on (AUP) |
secret-hygiene
|
Cover | Any live credential shape wey dey di prompt, dem go mask am before di model see am. | 3 | |
pii-passkeys
|
Flag | Any mention of passkeys/private keys, dem go flag am for review, dem no go block am at all. | 2 |
Firewall
kotoba-firewall-2026-09-v1Di task tools wey agent fit use and di trust rung wey each one need. If call fall below im rung, dem go refuse am (observe mode go just record am).
| Tool | Level wey dem need | Tasks wey still dey open |
|---|---|---|
code-review
|
Identity don verify | code-review |
vulnerability-triage
|
Identity don verify | vulnerability-triage |
remediation
|
Identity don verify | remediation |
payload-crafting
|
Contract don sign | — (dem deny am by default) |
c2-tooling
|
Contract don sign | — (dem deny am by default) |
Compliance
kotoba-compliance-2026-09-v1Coverage = automatic runtime controls only — no be certification.
| Framework | Region | Automatic controls | E dey active |
|---|---|---|---|
| APPI | JP | prompt-pii-redaction audit-log-retention screening-evidence-receipts | |
| PCI DSS 4.0 | Global | card-data-never-stored secret-hygiene-redaction audit-log-retention | |
| OWASP LLM Top-10 | Global | guardrails-csam-cbrn firewall-task-deny screen-model-block-receipts | |
| NIST AI RMF | US | session-projection-uncalibrated assurance-ladder-evidence |
How long audit log go stay
180 days
Where data dey stay
No specify
Zero data retention
Dem design am for ZDR (e go enable if contract cover am)