Security & privacy architecture

Privacy testing that keeps evidence inside your boundary.

AgentLeak is local-first, deterministic and redacted by default. Use the open-source analyzer offline, self-host the full platform, or send synthetic traces to the hosted service.

The security control loop

Build privacy controls around evidence.

LOCAL EXECUTION
POLICYTRACEREPORTdecision signed · 2026-07-20 18:42 UTC

Keep evidence inside the boundary

Run detection and scoring in-process, with policy, trace and report digests joined at the decision point.

TRACE-LINKED PROOF
POLICY .40v1.4v1.8v2.1

Read regressions before release

Compare exposure over time and see when a new run crosses the project’s defined privacy threshold.

PROJECT ISOLATION
SOURCEvault.emailAGENT BmemorySINK · L3tool_call10:42.0110:42.1810:42.31

See every boundary crossing

Follow a redacted value from its source to the disclosure event without opening another project’s evidence.

Local by default

The core detector and AgentRisk scorer run in-process with regex, dictionaries, entropy and optional Presidio. No account, network call or hosted model is required.

  • No telemetry or phone-home
  • Raw matches redacted in reports
  • Synthetic scenarios for safe validation

Trace-linked evidence

Every finding keeps its channel, event and severity context. Reviewers can see where data entered, which agent handled it and where disclosure occurred.

  • Eight normalized execution channels
  • Leak provenance and topology
  • Stable report digests for CI

Bounded automation

Projects define a vault, detectors and policy. Autonomous agents receive scoped keys and machine-readable remediation without access to another project’s evidence.

  • Per-project credentials
  • Bring your own model key
  • Explicit quotas and rate limits