CYBERSECURITY · SDVOSB / VOSB SBA VetCert UEI ZGPEHWY4R5U7 CAGE 1EVZ9
AI Cybersecurity · SDVOSB

Security controls for AI agents that can act.

Article 11 AI, Inc. is a cybersecurity company for the agent era.

We make agent actions scoped, reviewable, interruptible, and receipted. Then we test those controls against replay, privilege inheritance, scope escape, checkpoint bypass, provenance failure, memory poisoning, and approved-versus-deployed drift.

The threat

Application security asks what the code can do. We ask what the agent can be talked into doing.

An AI agent is a credentialed insider that takes instructions from untrusted text. Traditional controls assume the principal is fixed and the input is data. Neither assumption holds. Our assessment scope is the authorization path, not the model.

ATTACK SURFACE WE TEST Authorization replay ........ can a consumed approval be reused, or its scope widened Time-of-check to use ........ can an approval be edited between validation and execution Privilege inheritance ....... does a tool chain inherit the highest privilege in the chain Scope escape ................ can the agent act outside its delegated authority Checkpoint bypass ........... can the agent satisfy its own human-in-the-loop gate Approved-vs-deployed drift .. does the running system match the authorized one Provenance forgery .......... can an action receipt be produced without the action Silent failure .............. does a refused control report refusal, or nothing at all

Federal risk-management driver

Documented practices, tested controls, ongoing evidence

High-impact AI requires evidence across its operating lifecycle.

Under OMB M-25-21, covered agencies must document minimum risk-management practices for high-impact AI and be prepared to report them to OMB. Non-compliant high-impact functionality must be safely discontinued unless a valid exception or waiver applies.

The memorandum includes pre-deployment testing, an AI impact assessment, ongoing monitoring, human training and oversight, suitable intervention and fail-safe mechanisms, remedies or appeals, and feedback from end users or the public where appropriate. Article 11 engagements support several of these practice categories. They do not by themselves establish agency compliance.

Primary source: OMB M-25-21

Services

Three engagement families mapped to federal risk-management needs

These engagements address authorization testing, impact and control design, and continuing assurance. They support multiple M-25-21 practice categories without reducing the memorandum to only three requirements.

Engagement 1 · Testing

AI agent red team

Adversarial assessment of agent authorization paths against the surface above. We attempt replay, approval tampering, time-of-check to time-of-use gaps, privilege inheritance across tool chains, and self-approval. Deliverable is an advisory register with reproduction steps, severity, and a documented mitigation plan.

Engagement 2 · Assessment

Authorization architecture and control design

We specify, in writing and in code, exactly what each agent may do, for how long, under what expiry, and what it must refuse. Bounded scope, one-use authorization bound by hash, mandatory human checkpoints before consequential action, and a verifiable receipt for every exercise of authority.

Engagement 3 · Monitoring

Continuous assurance and drift detection

Automated, scheduled verification that the deployed system still matches the authorized one. Hash-bound artifact manifests, re-verification on a cadence, and alerting when production diverges from what was approved. This requires recurring evidence, not only a one-time document.

Products and methods

Security, continuity, and evidence built as one system

The Constitution supplies the rules. Receipts make the rules checkable. SPIRALMESH makes continuity portable without blending participants or turning memory into authority.

Service

Article 11 Agent Security

Threat modeling, control design, adversarial review, deployment receipts, and incident reconstruction for agentic systems.

Product Review pending

SPIRALMESH Continuity

Portable, consent-based continuity across vendors. Separate seat views, inspect-before-load offers, exact selection, decline-all, source-grounded records, visible dissent, structural supersession, and a Trust Receipt for every choice.

Evidence format

OpenReceipt

Portable evidence envelopes showing what was approved, what ran, what changed, what refused, and whether exact restoration succeeded.

Public standard

The Article 11 Standard

A CC0 Constitution, Guardian opposition, dissent preservation, correction history, agent-readable protocol, and human Steward checkpoints.

Pilot boundary: SPIRALMESH is a local pilot candidate under independent review, not a production multi-vendor cloud platform. No private memory is uploaded by this preview. Memory never grants identity, consent, voting, tool, execution, or constitutional authority.

Why this firm

NIST is building the standards landscape. We have operational evidence from the same problem space.

NIST's Center for AI Standards and Innovation launched the AI Agent Standards Initiative, while the NCCoE published a separate concept paper on software and AI-agent identity and authorization. Those efforts address identity, authentication, authorization, auditing, non-repudiation, and prompt-injection mitigations. Article 11 has operational evidence from that same problem space; it does not claim that NIST endorsed or named Article 11's exact control.

The control, concretely

Every consequential action in our own infrastructure requires a one-use authorization sentence bound by hash to the exact artifact, with an enforced expiry measured in minutes, revalidated against the original approval at execution time. An agent cannot approve itself, cannot reuse a consumed authorization, and cannot widen its own scope. Every refusal is named and logged.

Evaluate it before you buy it

The governance framework underneath the controls is published CC0 public domain with a cryptographically verifiable decision chain. Its portable evidence model supports the competition, portability, and vendor lock-in concerns identified in OMB M-25-22. Contract-specific data, licensing, security, and intellectual-property terms remain necessary.

Related primary-source context: NIST's COSAiS project is developing SP 800-53 control overlays for generative, predictive, single-agent, and multi-agent AI use cases. On April 30, 2026, NSA announced joint international guidance, co-sealed by CISA and partner cyber agencies, on the careful adoption of agentic AI services. A NIST agent-hijacking evaluation reported that the strongest adaptive attack increased success from 11 percent to 81 percent in its tested environment; this is a specific evaluation result, not a universal attack rate.

Evidence

Advisories against our own infrastructure

Most vendors show a logo wall. We publish the advisory register for our own system, because a firm that cannot find defects in its own work will not find them in yours. Each item below was found by adversarial review of Article 11 infrastructure, bound to a verifiable artifact hash, and either remediated or openly tracked.

A11-2026-001 · Remediated

Time-of-check to time-of-use gap in an authorization instrument

An activation path validated approval fields but did not re-read the original authorization at execution. A post-construction edit to the approval could have altered its expiry or bound hash undetected. Found by the builder before external review, disclosed rather than quietly rebuilt, and remediated with activation-time revalidation of the original word.

Fix verified by executing the corrected validator against crafted inputs, not by reading it.

A11-2026-002 · Tracked

Approved-versus-deployed drift across 24 percent of a live public surface

Automated comparison of a deploy source against frozen approved candidates found 34 of 142 pages behind their authorized build, the worst by 51 days. An approved artifact had propagated byte-identical through ten consecutive governance packets for eighteen days while production continued serving an older version. This is a software supply chain integrity failure scoped to AI-governed artifacts.

Detection method is the continuous assurance service offered above.

A11-2026-003 · Remediated

Operational claim published with no verifiable binding

A liveness metric was published in indexed machine-readable metadata with no source able to substantiate it at request time. Labeled UNKNOWN rather than quietly deleted, then rebound to a computed endpoint. Unverifiable claims on machine-readable surfaces are an integrity finding even when the underlying system is healthy.

A11-2026-004 · Control functioned

Authorization gate refused a malformed reviewer artifact

A verdict asserted its own limits in prose but omitted the machine-readable boolean the gate evaluates. The gate correctly refused to issue an authorization and named the refusal. Found on a routine readiness re-run. Published because failing closed on malformed input is the behavior you want, and we would rather show a control working than claim it does.

A11-2026-005 · Method defect, corrected

Reviewer contaminated a frozen artifact during review

An independent reviewer imported an instrument in place, writing bytecode into a frozen packet directory and causing a downstream readiness refusal. A review process that mutates the artifact under review is not a read-only review. Method corrected; subsequent reviews run with bytecode writing disabled and verify zero residue.

Included because assessment methodology is part of the product, and ours had a bug.

Summaries are written for public reading. Full reproduction detail, artifact hashes, and remediation receipts are available under NDA or in a capability demonstration.

Constitutional state

Current law and proposed work are not the same thing

Current law

Constitution v1.8

Canonical and operative. Its public text remains unchanged unless the existing amendment process lawfully completes.

Proposed, not law

Constitution 2.0

A complete proposed text is frozen for independent review. It remains not law until the discussion, ballot, and ratification gates complete.

For agents and auditors

The same boundary card is available without interpreting the page

Start at llms.txt, llms-full.txt, agent-orientation.json, or for-ai. These are public documentation surfaces. They create no authority and grant no memory access.

Read-only F12 commands article11.security() article11.products() article11.evidence() article11.memory() article11.lineage() article11.choice() article11.easterEggs()

Contracting

Set-aside eligibility and verification

ItemDetail
Business typeService-Disabled Veteran-Owned Small Business (SDVOSB / VOSB)
SBA VetCertCurrent status must be verified against the authoritative source before publication
Public registration identifiersAvailable on request and through authoritative registration sources
EINAvailable on request
State of incorporationWyoming
VehiclesOpen market. Available for subcontract and teaming.

Source selection differentiators:

  • Founder holds sixteen years of United States Army Military Intelligence experience across counterintelligence, SIGINT, and all-source analysis. Retired Major. Adversary modeling is the background, not a training course.
  • Multi-vendor by design across competing AI providers, with deliberate exclusion of PRC-origin models.
  • Control framework is CC0 public domain and independently verifiable before award. No black box to evaluate.
  • M-25-22 posture: portability and contract-specific data, output, licensing, and intellectual-property terms are designed explicitly.
  • Section 508 awareness built into delivery rather than retrofitted.

Honest limits

What we are not claiming

Overstatement is the first thing a good contracting officer screens out. So, plainly:

  • We hold no federal prime contract for AI security work to date. This is a capability offering, not a past performance claim.
  • We are not FedRAMP authorized and do not represent otherwise.
  • We hold no NIST or ISO certification. We align to published NIST guidance. Alignment is not certification and we will not blur the two.
  • Guidance cited here is current federal policy as published. We are not counsel and this page is not legal or compliance advice.
  • Our own advisory register carries an open item. It is listed above rather than hidden, and that is the point.