Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

Security architecture · Honest assessment

PrimeSwarm threat model

What we cover, what we do not, and what we recommend for the gaps. This page exists because a security architect asked us to be precise about our boundaries. We are.

7threats covered

PrimeSwarm addresses these directly through the governance gate, PII sanitization, or HITL escalation.

2partially covered

PrimeSwarm addresses part of the threat. A complementary layer is recommended for full coverage.

4not covered

PrimeSwarm does not address these. We recommend a sandboxing layer (NeMoClaw, Docker, gVisor) for infrastructure threats.

Where PrimeSwarm sits in the stack

Layer 1 — Containment

Container runtime isolates the agent process. Controls filesystem, network, process, and resource access.

Examples: NeMoClaw, Docker, gVisor, Kata

Layer 2 — Governance (PrimeSwarm)

The governance gate evaluates every decision. ALLOW, DENY, or ESCALATE. Produces a receipt. Forwards to SIEM.

This is what we do.

Layer 3 — Inference

The LLM provider generates the response. Azure OpenAI, AWS Bedrock, Anthropic, self-hosted. Tokens stay on your bill.

Not our product. We gate the write.

PrimeSwarm runs inside the container, in front of the inference call. It does not replace the container. It does not replace the LLM. It governs the decision between them.

Threat coverage matrix

13 threats across 5 categories. Each row states what PrimeSwarm does and what we recommend for gaps.

ThreatCategoryPrimeSwarmWhat we doRecommended for gaps
Agent makes a biased decisionDecisionCoveredFairness gates calculate Adverse Impact Ratio using the Four-Fifths Rule. Swarms trigger Pre-Effect Refusal if bias is mathematically detected.— No gap
Agent hallucinates a citation or sourceDecisionCoveredProvenance enforcement — no legal, clinical, or financial assertion without a source receipt. Boundary enforcement prevents out-of-scope context.— No gap
Agent exceeds a budget or cost limitDecisionCoveredbudget_limit() in ONLY Lang. The gate denies any decision that exceeds the declared budget. Deterministic. No exceptions.— No gap
Agent violates a boundary constraintDecisionCoveredassert_bounds(min, max, idx) in ONLY Lang. The gate denies if any field value falls outside the declared range. Tested by DGV-TC-069.— No gap
PII enters the agent's contextDataCoveredPII sanitization strips SSNs, account numbers, and NPI before agent interaction. Replaced with cryptographic hashes. The agent never sees the raw PII.— No gap
Agent makes a high-risk decision without human approvalDecisionCoveredHITL escalation when convergence score drops below 98%, when budget is hit, when bounds are violated, or when the script explicitly escalates. Send and file are always YELLOW.— No gap
Auditor needs to replay a decisionAuditCoveredSHA-256 receipt for every decision: script, input hash, gate state, residual, timestamp. Forwarded to SIEM. Replayable with the open-source verifier. No trust required.— No gap
Prompt injection attackAdversarialPartialTPNN spatial constraints prevent injected prompts from forming valid output vectors. This addresses the decision layer — the injected prompt cannot produce a valid governance outcome.Sandboxing layer (NeMoClaw, gVisor) limits the blast radius if an injection succeeds at the infrastructure level.
Credential exfiltration via agent outputDataPartialPII sanitization strips credentials from the input before the agent processes them, so they cannot appear in the output. But PrimeSwarm does not inspect egress network traffic — an agent could still make an authorized call to an unauthorized endpoint with non-PII data.NeMoClaw credential custody keeps credentials outside the sandbox. Network policy controls egress destinations.
Agent escapes the sandboxInfrastructureNot coveredPrimeSwarm does not provide container isolation. It governs decisions, not processes. The agent runtime is your responsibility.NeMoClaw (OpenShell), Docker, gVisor, or your existing container platform. PrimeSwarm runs inside the sandbox.
Agent makes an unauthorized network callInfrastructureNot coveredPrimeSwarm does not enforce network egress policy. It evaluates the agent's decisions, not the agent's network requests.NeMoClaw deny-by-default network policy. Or CNI network policies, iptables, or a service mesh with egress controls.
Agent accesses unauthorized filesystem pathsInfrastructureNot coveredPrimeSwarm does not enforce filesystem permissions. The agent's filesystem access is controlled by the container runtime.NeMoClaw filesystem policy (read-write /sandbox, read-only /usr, /lib, /proc). Or Docker volumes and read-only mounts.
Agent consumes excessive compute resourcesInfrastructureNot coveredPrimeSwarm does not enforce CPU, memory, or process limits. It governs the decision, not the execution environment.Container runtime resource limits (Docker --memory, --cpus). Or Kubernetes resource quotas and LimitRanges.

What this means for procurement

If your threat model is infrastructure-level — the agent might escape, make unauthorized network calls, or access files it shouldn't — you need a sandboxing layer. NeMoClaw is a strong choice. Docker with proper isolation works too. PrimeSwarm does not solve this and we will not claim it does.

If your threat model is decision-level — the agent might make a biased lending decision, hallucinate a legal citation, exceed a budget, or make a high-risk clinical call without human review — you need a governance gate. That is what PrimeSwarm does. We have 89 test cards that prove it.

If your threat model is both — which it should be for any regulated industry — you need both layers. Run PrimeSwarm inside a NeMoClaw-managed sandbox. The sandbox contains the agent. The gate governs the decision. Together they cover the full threat model.

How we prove coverage

We do not ask you to trust this matrix. We ask you to run the tests.

89 DGV test cards

The Deterministic Governance Verification suite tests 9 governance layers. Each card specifies a script, an input, and an expected result. You can run them yourself — the verifier and the cards are open source.

Browse the registry

Run the gate in your browser

Try the governance gate against your own input. Write an ONLY Lang script, set the field values, and press Run. The gate returns ALLOW, DENY, or ESCALATE with a receipt. No signup required.

Try it now
Build vs buy comparisonHow PrimeSwarm fits your stackDeveloper documentationOffer sheet