What did the agent read?
Governed retrieval records the permitted context and refuses access when identity, lineage, purpose, or locality rules do not hold.
Enterprise proof session
Bring a policy, data-locality constraint, or high-risk operation. We will show the decision path, trigger a typed refusal, and inspect the retained evidence with your security and operations teams.
A proof session is scoped to the selected deployment and policy. The public sample is illustrative and is not presented as customer or production evidence.
The proof path
Governed retrieval records the permitted context and refuses access when identity, lineage, purpose, or locality rules do not hold.
Actions are prepared behind policy checks, independently read back where the provider permits it, and assigned an explicit outcome.
Proof artifacts are content-bound and designed for verification outside the product, without asking an auditor to trust a model explanation.
The moment that matters
CLOUD_EGRESS_BLOCKEDThe system stops before the external side effect, returns a stable reason code, and retains the decision evidence. A refusal is only claimed as live proof when that session's artifact is archived.