Security architecture · Honest assessment
PrimeSwarm threat model
What we cover, what we do not, and what we recommend for the gaps. This page exists because a security architect asked us to be precise about our boundaries. We are.
PrimeSwarm addresses these directly through the governance gate, PII sanitization, or HITL escalation.
PrimeSwarm addresses part of the threat. A complementary layer is recommended for full coverage.
PrimeSwarm does not address these. We recommend a sandboxing layer (NeMoClaw, Docker, gVisor) for infrastructure threats.
Where PrimeSwarm sits in the stack
Layer 1 — Containment
Container runtime isolates the agent process. Controls filesystem, network, process, and resource access.
Examples: NeMoClaw, Docker, gVisor, Kata
Layer 2 — Governance (PrimeSwarm)
The governance gate evaluates every decision. ALLOW, DENY, or ESCALATE. Produces a receipt. Forwards to SIEM.
This is what we do.
Layer 3 — Inference
The LLM provider generates the response. Azure OpenAI, AWS Bedrock, Anthropic, self-hosted. Tokens stay on your bill.
Not our product. We gate the write.
PrimeSwarm runs inside the container, in front of the inference call. It does not replace the container. It does not replace the LLM. It governs the decision between them.
Threat coverage matrix
13 threats across 5 categories. Each row states what PrimeSwarm does and what we recommend for gaps.
| Threat | Category | PrimeSwarm | What we do | Recommended for gaps |
|---|---|---|---|---|
| Agent makes a biased decision | Decision | Covered | Fairness gates calculate Adverse Impact Ratio using the Four-Fifths Rule. Swarms trigger Pre-Effect Refusal if bias is mathematically detected. | — No gap |
| Agent hallucinates a citation or source | Decision | Covered | Provenance enforcement — no legal, clinical, or financial assertion without a source receipt. Boundary enforcement prevents out-of-scope context. | — No gap |
| Agent exceeds a budget or cost limit | Decision | Covered | budget_limit() in ONLY Lang. The gate denies any decision that exceeds the declared budget. Deterministic. No exceptions. | — No gap |
| Agent violates a boundary constraint | Decision | Covered | assert_bounds(min, max, idx) in ONLY Lang. The gate denies if any field value falls outside the declared range. Tested by DGV-TC-069. | — No gap |
| PII enters the agent's context | Data | Covered | PII sanitization strips SSNs, account numbers, and NPI before agent interaction. Replaced with cryptographic hashes. The agent never sees the raw PII. | — No gap |
| Agent makes a high-risk decision without human approval | Decision | Covered | HITL escalation when convergence score drops below 98%, when budget is hit, when bounds are violated, or when the script explicitly escalates. Send and file are always YELLOW. | — No gap |
| Auditor needs to replay a decision | Audit | Covered | SHA-256 receipt for every decision: script, input hash, gate state, residual, timestamp. Forwarded to SIEM. Replayable with the open-source verifier. No trust required. | — No gap |
| Prompt injection attack | Adversarial | Partial | TPNN spatial constraints prevent injected prompts from forming valid output vectors. This addresses the decision layer — the injected prompt cannot produce a valid governance outcome. | Sandboxing layer (NeMoClaw, gVisor) limits the blast radius if an injection succeeds at the infrastructure level. |
| Credential exfiltration via agent output | Data | Partial | PII sanitization strips credentials from the input before the agent processes them, so they cannot appear in the output. But PrimeSwarm does not inspect egress network traffic — an agent could still make an authorized call to an unauthorized endpoint with non-PII data. | NeMoClaw credential custody keeps credentials outside the sandbox. Network policy controls egress destinations. |
| Agent escapes the sandbox | Infrastructure | Not covered | PrimeSwarm does not provide container isolation. It governs decisions, not processes. The agent runtime is your responsibility. | NeMoClaw (OpenShell), Docker, gVisor, or your existing container platform. PrimeSwarm runs inside the sandbox. |
| Agent makes an unauthorized network call | Infrastructure | Not covered | PrimeSwarm does not enforce network egress policy. It evaluates the agent's decisions, not the agent's network requests. | NeMoClaw deny-by-default network policy. Or CNI network policies, iptables, or a service mesh with egress controls. |
| Agent accesses unauthorized filesystem paths | Infrastructure | Not covered | PrimeSwarm does not enforce filesystem permissions. The agent's filesystem access is controlled by the container runtime. | NeMoClaw filesystem policy (read-write /sandbox, read-only /usr, /lib, /proc). Or Docker volumes and read-only mounts. |
| Agent consumes excessive compute resources | Infrastructure | Not covered | PrimeSwarm does not enforce CPU, memory, or process limits. It governs the decision, not the execution environment. | Container runtime resource limits (Docker --memory, --cpus). Or Kubernetes resource quotas and LimitRanges. |
What this means for procurement
If your threat model is infrastructure-level — the agent might escape, make unauthorized network calls, or access files it shouldn't — you need a sandboxing layer. NeMoClaw is a strong choice. Docker with proper isolation works too. PrimeSwarm does not solve this and we will not claim it does.
If your threat model is decision-level — the agent might make a biased lending decision, hallucinate a legal citation, exceed a budget, or make a high-risk clinical call without human review — you need a governance gate. That is what PrimeSwarm does. We have 89 test cards that prove it.
If your threat model is both — which it should be for any regulated industry — you need both layers. Run PrimeSwarm inside a NeMoClaw-managed sandbox. The sandbox contains the agent. The gate governs the decision. Together they cover the full threat model.
How we prove coverage
We do not ask you to trust this matrix. We ask you to run the tests.
89 DGV test cards
The Deterministic Governance Verification suite tests 9 governance layers. Each card specifies a script, an input, and an expected result. You can run them yourself — the verifier and the cards are open source.
Browse the registryRun the gate in your browser
Try the governance gate against your own input. Write an ONLY Lang script, set the field values, and press Run. The gate returns ALLOW, DENY, or ESCALATE with a receipt. No signup required.
Try it now