Security

Defense in depth.

Autonomous workers can be run with layered safeguards — from network-level SSRF guards to prompt-injection detection, secret scanning, governance gates and append-only verification receipts.

Security Layers

Layered safeguards for worker actions

Depending on runtime configuration and the operation, outbound requests, tool calls and memory writes can pass through validation and review gates. Rejections and errors are surfaced for operator inspection.

🛡️
SSRF Guard

Blocks loopback, RFC1918, link-local, CGNAT, and metadata IPs. Per-hop redirect validation with a configured hop limit helps reduce DNS rebinding and open-redirect abuse.

🧬
Prompt Injection Defense

Pattern-based checks cover phrases such as ignore_previous, disregard_above, you_are_now and system_prompt_leak. Untrusted content can be wrapped with boundary markers before it enters the LLM context.

🔒
Protected Surfaces

config.toml, memory.db, bible.md, safety.md, secrets.toml, .env, and credentials are blocked from agent modification. Critical configuration is read-only at the tool level.

🔑
Secret Scanning

API keys (sk-, AKIA, ghp_, xoxb-, Bearer tokens, PEM blocks) are detected and blocked before they can reach the memory store or be exposed in tool outputs.

⛔
Destructive Command Blocking

Pattern checks can block rm -rf /, mkfs, fork bombs, dd of=/dev, chmod -R 777 /, and other catastrophic shell commands before they reach the executor.

🔄
Doom Loop Detection

Repeated tool-call patterns can trigger warnings or stops according to configured thresholds, helping operators review runaway behavior before side effects accumulate.

📋
Verification Receipts

An append-only JSONL ledger can record typed verification receipts, giving operators an audit trail to inspect alongside failures and approvals.

🔐
API Authentication

Bearer token or X-Api-Key header required for non-loopback binding. Authentication is mandatory when the server is exposed beyond localhost — no accidental public APIs.

⏱️
Rate Limiting

A sliding-window policy can limit requests per authenticated principal and return 429 with Retry-After headers when the configured limit is exceeded.

🌐
Fetch Safety

Configured response-size and text-length limits, together with per-hop SSRF checks on redirects, help reduce memory exhaustion and internal-network exfiltration.

✋
Approval Gates

save_contacts, git_push, and other side-effect tools require explicit human approval before execution. The agent requests, the operator decides.

🌐
CORS Policy

Permissive CORS only when API authentication is enabled. With auth disabled, CORS is restricted to prevent unauthorized cross-origin access to the agent API.

Verification Pipeline

Sequential email verification

A configured email-verification workflow can run through sequential stages, with typed receipts for review. Failures may short-circuit the pipeline according to its policy; results still require operator judgment.

1
Syntax

RFC 5322 validation. Rejects malformed addresses before any network call.

→
2
MX Lookup

DNS MX record resolution. Domains without mail exchangers are rejected.

→
3
Disposable Detection

Known disposable email providers are flagged and filtered out.

→
4
Role-based Check

info@, admin@, support@ and similar role addresses are flagged as low-value.

→
5
SMTP Probe

Live SMTP handshake to verify the mailbox actually exists without sending mail.

Hardware-Grade Isolation

The Ironclad Credentials Vault

API keys, passwords, and database tokens are encrypted with AES-256-GCM via the Rust ring crate. Secrets are resolved in memory before TLS dispatch — LLM prompts never see plaintext credentials.

Fathom Enterprise Security Credentials Vault

Fig 5.1 — Hardware Credentials Vault: AES-256-GCM encrypted key derivation with zero LLM prompt visibility and fail-closed audit log telemetry.

Regulatory Audits

Autonomous Legal & Compliance Verification

Multi-jurisdiction contract and policy audits: evaluating vendor Master Services Agreements against GDPR, CCPA, and statutory liability limits with paragraph-level citation traceability.

Legal & Compliance Document Auditor

Fig 5.2 — Regulatory Document Auditor: Automated compliance evaluation across 200 vendor agreements in under 30 minutes.

Pattern-based
prompt-injection checks
Policy-driven
destructive-command checks
Configurable
verification stages
Auditable
rejections and failures surfaced for review

Make worker actions reviewable

Choose and configure the safeguards, authentication, rate limits and approval gates that fit your deployment. Read the security architecture and verify the active policy in the documentation.