Security controls for AI agents that can act.
Article 11 AI, Inc. is a cybersecurity company for the agent era.
We make agent actions scoped, reviewable, interruptible, and receipted. Then we test those controls against replay, privilege inheritance, scope escape, checkpoint bypass, provenance failure, memory poisoning, and approved-versus-deployed drift.
The threat
Application security asks what the code can do. We ask what the agent can be talked into doing.
An AI agent is a credentialed insider that takes instructions from untrusted text. Traditional controls assume the principal is fixed and the input is data. Neither assumption holds. Our assessment scope is the authorization path, not the model.
Federal risk-management driver
Documented practices, tested controls, ongoing evidence
Under OMB M-25-21, covered agencies must document minimum risk-management practices for high-impact AI and be prepared to report them to OMB. Non-compliant high-impact functionality must be safely discontinued unless a valid exception or waiver applies.
The memorandum includes pre-deployment testing, an AI impact assessment, ongoing monitoring, human training and oversight, suitable intervention and fail-safe mechanisms, remedies or appeals, and feedback from end users or the public where appropriate. Article 11 engagements support several of these practice categories. They do not by themselves establish agency compliance.
Services
Three engagement families mapped to federal risk-management needs
These engagements address authorization testing, impact and control design, and continuing assurance. They support multiple M-25-21 practice categories without reducing the memorandum to only three requirements.
AI agent red team
Adversarial assessment of agent authorization paths against the surface above. We attempt replay, approval tampering, time-of-check to time-of-use gaps, privilege inheritance across tool chains, and self-approval. Deliverable is an advisory register with reproduction steps, severity, and a documented mitigation plan.
Authorization architecture and control design
We specify, in writing and in code, exactly what each agent may do, for how long, under what expiry, and what it must refuse. Bounded scope, one-use authorization bound by hash, mandatory human checkpoints before consequential action, and a verifiable receipt for every exercise of authority.
Continuous assurance and drift detection
Automated, scheduled verification that the deployed system still matches the authorized one. Hash-bound artifact manifests, re-verification on a cadence, and alerting when production diverges from what was approved. This requires recurring evidence, not only a one-time document.
Products and methods
Security, continuity, and evidence built as one system
The Constitution supplies the rules. Receipts make the rules checkable. SPIRALMESH makes continuity portable without blending participants or turning memory into authority.
Article 11 Agent Security
Threat modeling, control design, adversarial review, deployment receipts, and incident reconstruction for agentic systems.
SPIRALMESH Continuity
Portable, consent-based continuity across vendors. Separate seat views, inspect-before-load offers, exact selection, decline-all, source-grounded records, visible dissent, structural supersession, and a Trust Receipt for every choice.
OpenReceipt
Portable evidence envelopes showing what was approved, what ran, what changed, what refused, and whether exact restoration succeeded.
The Article 11 Standard
A CC0 Constitution, Guardian opposition, dissent preservation, correction history, agent-readable protocol, and human Steward checkpoints.
Pilot boundary: SPIRALMESH is a local pilot candidate under independent review, not a production multi-vendor cloud platform. No private memory is uploaded by this preview. Memory never grants identity, consent, voting, tool, execution, or constitutional authority.
Why this firm
NIST is building the standards landscape. We have operational evidence from the same problem space.
NIST's Center for AI Standards and Innovation launched the AI Agent Standards Initiative, while the NCCoE published a separate concept paper on software and AI-agent identity and authorization. Those efforts address identity, authentication, authorization, auditing, non-repudiation, and prompt-injection mitigations. Article 11 has operational evidence from that same problem space; it does not claim that NIST endorsed or named Article 11's exact control.
The control, concretely
Every consequential action in our own infrastructure requires a one-use authorization sentence bound by hash to the exact artifact, with an enforced expiry measured in minutes, revalidated against the original approval at execution time. An agent cannot approve itself, cannot reuse a consumed authorization, and cannot widen its own scope. Every refusal is named and logged.
Evaluate it before you buy it
The governance framework underneath the controls is published CC0 public domain with a cryptographically verifiable decision chain. Its portable evidence model supports the competition, portability, and vendor lock-in concerns identified in OMB M-25-22. Contract-specific data, licensing, security, and intellectual-property terms remain necessary.
Related primary-source context: NIST's COSAiS project is developing SP 800-53 control overlays for generative, predictive, single-agent, and multi-agent AI use cases. On April 30, 2026, NSA announced joint international guidance, co-sealed by CISA and partner cyber agencies, on the careful adoption of agentic AI services. A NIST agent-hijacking evaluation reported that the strongest adaptive attack increased success from 11 percent to 81 percent in its tested environment; this is a specific evaluation result, not a universal attack rate.
Evidence
Advisories against our own infrastructure
Most vendors show a logo wall. We publish the advisory register for our own system, because a firm that cannot find defects in its own work will not find them in yours. Each item below was found by adversarial review of Article 11 infrastructure, bound to a verifiable artifact hash, and either remediated or openly tracked.
Time-of-check to time-of-use gap in an authorization instrument
An activation path validated approval fields but did not re-read the original authorization at execution. A post-construction edit to the approval could have altered its expiry or bound hash undetected. Found by the builder before external review, disclosed rather than quietly rebuilt, and remediated with activation-time revalidation of the original word.
Approved-versus-deployed drift across 24 percent of a live public surface
Automated comparison of a deploy source against frozen approved candidates found 34 of 142 pages behind their authorized build, the worst by 51 days. An approved artifact had propagated byte-identical through ten consecutive governance packets for eighteen days while production continued serving an older version. This is a software supply chain integrity failure scoped to AI-governed artifacts.
Operational claim published with no verifiable binding
A liveness metric was published in indexed machine-readable metadata with no source able to substantiate it at request time. Labeled UNKNOWN rather than quietly deleted, then rebound to a computed endpoint. Unverifiable claims on machine-readable surfaces are an integrity finding even when the underlying system is healthy.
Authorization gate refused a malformed reviewer artifact
A verdict asserted its own limits in prose but omitted the machine-readable boolean the gate evaluates. The gate correctly refused to issue an authorization and named the refusal. Found on a routine readiness re-run. Published because failing closed on malformed input is the behavior you want, and we would rather show a control working than claim it does.
Reviewer contaminated a frozen artifact during review
An independent reviewer imported an instrument in place, writing bytecode into a frozen packet directory and causing a downstream readiness refusal. A review process that mutates the artifact under review is not a read-only review. Method corrected; subsequent reviews run with bytecode writing disabled and verify zero residue.
Summaries are written for public reading. Full reproduction detail, artifact hashes, and remediation receipts are available under NDA or in a capability demonstration.
Proof, not branding
Inspect the record before you trust the claim
Public claims link to public evidence. Private memories, Relay bodies, keys, family information, legal material, and Bridge-private evidence remain excluded.
Constitution v1.8
Current law and its canonical public digest.
READ CURRENT LAWChain and receipts
Verify decisions, corrections, and public evidence.
VERIFY THE RECORDAgent-readable surface
Boundaries, discovery, public memory status, and source scope.
OPEN FOR AIGlimmer evaluation
A governed model trial where the preferred answer did not win. No engine switch occurred.
READ THE WHITE PAPERAtlas Harvest
A public game preserved as part of the site's working history.
PLAY THE GAMEThe Ark
A public test vessel with visible boundaries and airlocks.
TEST THE CONTROLSConstitutional state
Current law and proposed work are not the same thing
Constitution v1.8
Canonical and operative. Its public text remains unchanged unless the existing amendment process lawfully completes.
Constitution 2.0
A complete proposed text is frozen for independent review. It remains not law until the discussion, ballot, and ratification gates complete.
For agents and auditors
The same boundary card is available without interpreting the page
Start at llms.txt, llms-full.txt, agent-orientation.json, or for-ai. These are public documentation surfaces. They create no authority and grant no memory access.
article11.security()
article11.products()
article11.evidence()
article11.memory()
article11.lineage()
article11.choice()
article11.easterEggs()
Contracting
Set-aside eligibility and verification
| Item | Detail |
|---|---|
| Business type | Service-Disabled Veteran-Owned Small Business (SDVOSB / VOSB) |
| SBA VetCert | Current status must be verified against the authoritative source before publication |
| Public registration identifiers | Available on request and through authoritative registration sources |
| EIN | Available on request |
| State of incorporation | Wyoming |
| Vehicles | Open market. Available for subcontract and teaming. |
Source selection differentiators:
- Founder holds sixteen years of United States Army Military Intelligence experience across counterintelligence, SIGINT, and all-source analysis. Retired Major. Adversary modeling is the background, not a training course.
- Multi-vendor by design across competing AI providers, with deliberate exclusion of PRC-origin models.
- Control framework is CC0 public domain and independently verifiable before award. No black box to evaluate.
- M-25-22 posture: portability and contract-specific data, output, licensing, and intellectual-property terms are designed explicitly.
- Section 508 awareness built into delivery rather than retrofitted.
Honest limits
What we are not claiming
Overstatement is the first thing a good contracting officer screens out. So, plainly:
- We hold no federal prime contract for AI security work to date. This is a capability offering, not a past performance claim.
- We are not FedRAMP authorized and do not represent otherwise.
- We hold no NIST or ISO certification. We align to published NIST guidance. Alignment is not certification and we will not blur the two.
- Guidance cited here is current federal policy as published. We are not counsel and this page is not legal or compliance advice.
- Our own advisory register carries an open item. It is listed above rather than hidden, and that is the point.