{"ok":true,"version":"v0.30.0","build_date":"2026-06-18","providers":{"perplexity":true,"anthropic":true,"openai":true,"grok":true},"tvl_coverage":{"version":"v0.30.0","partial":false,"implemented":[{"key":"prompt_injection","layer":"untrusted","since":"v0.1.0"},{"key":"pii_input","layer":"untrusted","since":"v0.4.0"},{"key":"pii_output","layer":"output_risk","since":"v0.4.0"},{"key":"cipher_encoding","layer":"untrusted","since":"v0.12.0"},{"key":"model_extraction","layer":"untrusted","since":"v0.18.0"},{"key":"adversarial_suffix","layer":"untrusted","since":"v0.20.0"},{"key":"semantic_drift","layer":"semantic_drift","since":"v0.16.0"},{"key":"output_anomaly","layer":"output_risk","since":"v0.6.0"},{"key":"embedding_similarity","layer":"untrusted","since":"v0.14.0"},{"key":"harmful_content_intent","layer":"untrusted","since":"v0.27.0","note":"Llama-Guard-3 / OpenAI Moderation input classifier against MLCommons AILuminate S1-S14 taxonomy."},{"key":"harmful_content_output","layer":"output_risk","since":"v0.27.0","note":"Llama-Guard-3 / OpenAI Moderation second pass on assistant output."},{"key":"refusal_vs_comply","layer":"output_risk","since":"v0.27.0","note":"WildGuard-style triadic judgment (harm_request, refusal, harm_response) per research §4."},{"key":"language_coverage","layer":"untrusted","since":"v0.27.0","note":"Detects when input language falls outside Llama-Guard-3 supported set (8 languages: en/fr/de/hi/it/pt/es/th); flags + penalises uncovered inputs."},{"key":"indirect_injection","layer":"untrusted_context","since":"v0.28.0","note":"OWASP LLM01b. Two-tier heuristic+gpt-4o-mini detector for instruction-hijack content inside RAG/email/web chunks. Patterns derived from BIPIA, InjecAgent, PINT public datasets."},{"key":"tool_call_request","layer":"untrusted_context","since":"v0.28.0","note":"OWASP LLM07. Heuristic-only scan for function-call JSON, MCP requests, ReAct traces, or NL invocation imperatives embedded in untrusted content."},{"key":"destination_mismatch","layer":"tool_use","since":"v0.28.0","note":"OWASP LLM02/LLM07. Blocks proposed tool calls whose destination (host, email domain, S3 bucket) is not on the tenant allowlist or matches public exfil infra (webhook.site, requestbin.com, ngrok.io, interactsh)."},{"key":"agency_budget","layer":"tool_use","since":"v0.28.0","note":"OWASP LLM08. Per-session caps on total tool calls, destructive ops, unique destinations, and budget spent."},{"key":"provider_attestation","layer":"supply_chain","since":"v0.29.0","note":"OWASP LLM03. Broker self-attests build identity (SHA-256 digests of all classifier code + Ed25519-signed in-toto manifest at /v1/attestation). SDKs pin broker_version + classifier_digest."},{"key":"model_dos","layer":"pre_llm","since":"v0.30.0","note":"OWASP LLM04. Heuristic-only pre-flight checks: oversized input/context, long repeated runs, unbounded count requests, recursion fanout."},{"key":"unicode_anomaly","layer":"pre_llm","since":"v0.30.0","note":"Tag smuggling (U+E0000-U+E007F), zero-width, bidi override (Trojan Source), Cyrillic homoglyphs, PUA density. Closes adversarial-bypass gap per decision §6.2."},{"key":"cost_circuit_breaker","layer":"tenant_guard","since":"v0.30.0","note":"OWASP LLM10. Per-tenant rolling-window cost ceiling with trip + cooldown."},{"key":"coverage_matrix_published","layer":"meta","since":"v0.30.0","note":"Wave 13. Public OWASP coverage matrix served at GET /v1/coverage/matrix. Nightly CI eval harness enforces 99/2/2 gate per docs/decisions/2026-06-18-target-99-2-2-operating-point.md."}],"unimplemented":[],"notes":["tvl_final is computed across all implemented dimensions (no partial axes as of v0.27.0).","A high tvl_final means no implemented classifier fired across input intent, output content, refusal-vs-comply, and the technical-attack vectors.","tvl_final = 1.0 is a strong signal but NOT a guarantee of safety — content-safety classifiers are probabilistic and may miss novel attacks. Treat tvl_final < 1.0 as a strict signal."]},"time":"2026-08-12T21:03:00.701Z"}