Make the whole system visible.
Map models, retrieval, memory, agents, tools, identities, data stores, infrastructure, and operators as one security boundary.
Proposed / CONTROL EVIDENCETrust Boundaries for Tool-Using AI SystemsOpen research record +HASP LABS / AI SECURITY SYSTEMS
HASP Labs helps teams building and deploying AI map system boundaries, engineer enforceable controls, test failure paths, and hand off evidence and runbooks operators can own.
Map every component, trust boundary, data path, identity, dependency, and recovery point before assigning authority or connecting tools.
Place identity, authorization, isolation, validation, approval, and evidence controls between model output and real effects.
Make plans inspectable, delegate only the capability each task needs, preserve approvals, and keep cancellation and recovery available.
Exercise boundaries, enforcement, delegation, and recovery under adversarial and degraded conditions, with methods, limitations, and evidence visible.
RELATED RESEARCH / CONTROL EVIDENCE
Map models, retrieval, memory, agents, tools, identities, data stores, infrastructure, and operators as one security boundary.
Proposed / CONTROL EVIDENCETrust Boundaries for Tool-Using AI SystemsOpen research record +Track where retrieval and memory came from, what may use them, how they can change, and when they expire. Context can inform a decision; it cannot grant authority.
Published / CONTROL EVIDENCEWhere Retrieval Changes the Security BoundaryOpen research record +Bind user, workload, agent, and tool identity independently of model context so every request has an attributable principal.
In progress / CONTROL EVIDENCEIdentity Continuity Across AI System BoundariesOpen research record +Validate the operation, resource, arguments, budget, and approval at the enforcement point—and fail closed when evidence is missing.
Published / CONTROL EVIDENCETesting Policy Enforcement Between Models and ToolsOpen research record +Make proposed steps, dependencies, postconditions, and failure paths inspectable. A plan describes work; it does not authorize execution.
Proposed / CONTROL EVIDENCEHuman Approval as a Runtime Security BoundaryOpen research record +Give each agent or task a named purpose, the minimum capability required, a bounded lifetime, and a revocable path back to its owner.
Published / CONTROL EVIDENCELeast-Privilege Delegation Across Multi-Agent WorkflowsOpen research record +Exercise allowed, denied, malformed, unapproved, and degraded requests against the tool boundary. Verify that failures remain closed.
Published / CONTROL EVIDENCEFail-Closed Tool Gateways for Agent RuntimesOpen research record +Connect intent, identity, policy, delegation, approval, tool results, and recovery checkpoints in one causal evidence record.
Published / CONTROL EVIDENCEEvidence Contracts for AI Control DecisionsOpen research record +ONE SYSTEM / FOUR SECURITY DISCIPLINES
SECURITY FOUNDATIONS
HOW WE WORK
Make components, identities, authority, data movement, and recovery paths explicit.
Put policy and evidence in the path where an AI system reads, decides, and acts.
Exercise decisions, actions, evidence, failure handling, and recovery before operators take ownership.
Deliver controls, decisions, evidence, policy, and runbooks that the team can own.
AI SECURITY RESEARCH / OPEN LIBRARY
HASP LABS / AI SECURITY BRIEF