AEGIVORA — AGENT TOOL CONTROLS Release 0.3.0-rc.16 | Enterprise evaluation candidate | 21 September 2026 Working name; legal and trademark clearance pending. WHAT IT DOES A policy checkpoint for supported agent-to-tool calls. Explicit identities, tool/resource scopes, increasing task classifications, destination ceilings, exact-request approvals, duplicate-execution controls and audit records support controlled workflows. A separate deployment is intended for each organisation. Reference transport: JSON over HTTPS. Native MCP transport is not included. PUBLIC EVIDENCE https://aegivora.com/assurance Recorded local HTTPS workload and failure checks; not a live-service benchmark, independent assessment or customer acceptance. PUBLIC WALKTHROUGH https://aegivora.com/evaluate Five reproducible, recorded synthetic outcomes: authorized read; lower-trust send denied; exact-action approval pending; execution after approval; replay rejected. This is a recording from the gateway core, not a live customer test, independent assessment, representative load test or detection-accuracy proof. ENCRYPTION AND AI Ordinary calls use HTTPS; sensitive stored records use AES-256-GCM. The gateway can read ordinary payloads. Optional endpoint-encrypted tools require integration and keys at both endpoints; the gateway cannot inspect encrypted content. The hosted evaluation has no paid LLM configured. The optional local classifier is advisory and has known misses. Training changes candidate numerical weights, not application code or authorization. Live customer traffic is not training data. GOOD FIT TO INVESTIGATE An AI platform or application security team with one supported tool workflow that needs explicit allow/deny, data-flow and review controls across its systems. This is not a consumer antivirus, a universal DLP system or an autonomous SOC. Only routed calls are governed; the deployment must prevent direct tool bypass. SUGGESTED SCOPED EVALUATION 1. Agree one authorized integration and an isolated synthetic-data environment. 2. Define expected allowed and denied actions before testing. 3. Test identity/resource restrictions, data boundaries, exact approvals, replay, revoked credentials, uncertain tool outcomes, audit export and recovery. 4. Measure latency and failures with the agreed workload; no universal target or SLA is asserted. Record false alarms and missed attacks separately. 5. Record pass/fail evidence and unresolved requirements. Synthetic success does not authorize customer production use. RELEASE LIMITS Single-node trial deployment; no high availability or enterprise-scale proof. Developer verification and source/container scans are not independent assurance. CodeQL is skipped because of repository eligibility. Independent assessment, customer acceptance, independently held recovery keys, funded operations, support/legal terms, brand clearance and commercial onboarding remain gates. No certifications, customer references, guaranteed protection, superiority or acquisition interest are claimed. Public registration and paid plans are not open. INQUIRY INPUTS Agent framework; intended tool; data labels; hosting region; expected allow/deny cases; required identity and recovery controls. Use synthetic examples only. Do not share API keys, passwords or customer documents in an initial inquiry. The evaluation page will show the operator's business contact when configured.