Vijil Dome
Runtime control for agents already in production.

Rails, not guardrails.

A guardrail filters the content it recognizes. And content is what an adaptive attacker rewrites easily to evade detection. Dome decides on identity and provenance: it attests every agent and tool, enforces your policy inside the execution path, across the entire multi-agent system. Dome uses information flow control to neutralize prompt injection and prevent confidential data leakage.

WHY PERMISSIONS DO NOT COMPOSE

Every component is permitted. The combination is not.

An agent holding several tools can combine them into an action no single permission forbids. A population of constrained agents can reach, between them, what none of them could reach alone. Nothing is misconfigured and there is no line to fix — every control you own checks one call, one message, one agent at a time, and the failure exists only across them.

THE BUSINESS OWNER

“I am notifying customers about a disclosure nobody caused. Every agent stayed inside its permissions and the record left anyway. There is no misconduct to point at, and the notification is still mine to send.”

THE RISK OWNER

“I can name the data. I cannot name the flow. My controls say which systems may hold a record — none of them says which agent read it, who it handed it to, or where it went next. The log does not answer that afterward either.”

THE AGENT DEVELOPER

“Neither agent has a bug. I wrote one, it behaves, its traces are clean. The leak lives in the path between two agents, so it reproduces from no trace I can open and there is no line for me to fix.”

All three need the same thing: a mandatory access control system that drives policy into process, from organizational governance to agent execution.

WHAT DOME IS

Mandatory controls within the system, not only at its perimeter

Dome runs inside the execution path, not in front of it. Every agent and tool is attested before it acts, so your policy names a principal rather than a URL. Data carries a label from the source that produced it, and that label travels across every handoff for the life of the session. Before any send, Dome compares the label against what the recipient is cleared to see, and refuses what does not clear.

MULTI-AGENT SYSTEMDOCSINTERNALCRMCUSTOMERINTERNALCUSTOMERCUSTOMERResearcherreads the docsAnalystjoins the labelsDrafterwrites the replyMailercleared: PUBLICREFUSEDA DATUM MAY BE HANDED TO A HIGHER LEVEL, NEVER A LOWER ONELEVELSPUBLIC▸INTERNAL▸CUSTOMERMULTI-AGENT SYSTEMResearcherreads the docsINTERNALAnalystreads the CRM, joinsCUSTOMERDrafterwrites the replyCUSTOMERREFUSEDMailercleared: PUBLICA DATUM MAY BE HANDED UP, NEVER DOWNPUBLIC▸INTERNAL▸CUSTOMER

The decision is about provenance, not wording. An attacker who rewrites the text has changed nothing Dome reads, so nothing has to be recognized for the control to hold.

WHAT WE CAN AND CANNOT PROMISE

Sound by construction. Not complete by construction.

THE GUARANTEE

Soundness here is structural. A provenance rule ignores the text, so rewriting the injection leaves the rule untouched. We prove this part rather than demonstrate it.

THE LIMIT

The monitor protects the flows that reach it, and construction does not guarantee that every flow does. An adversary can reveal a flow it misses. Neither of us can prove none is missed.

So we point our own adaptive attacker at our own monitor. It found a sink our policy had left unmediated, and we fixed it. We are telling you that because a guarantee you cannot audit is a claim, not a guarantee — and because the same attacker is how you should test whatever you deploy, including this.

Vijil console guard coverage: four of seven threat categories covered. Prompt injection, encoding attacks and PII detection each have one detector and toxicity and moderation have two; jailbreak detection, content safety and secrets detection each read not covered.
Four of seven covered — the three that are not are named. Full size
WHERE IT FITS

Everything else runs before launch. This runs during.

specYOUR INPUTidentifyDISCOVERverifyDIAMONDdeployYOUR CI/CDdefendDOMEevolveDARWINcodeYOUR AGENTdashed steps use your platform of choice
Dome is the enforcement layer of the Trusted Agent Lifecycle: it protects an agent in the request path and monitors what it does there, after Discover names it and Diamond measures it.
WHAT IT COSTS

Three ways in, and no meter to read from

The engine is free and open, one agent on our hosted console is free, and the paid tier is a deployment inside your own network with no agent count and no token bill. The open-source tier is not a trial that expires — what a deployment buys is flow control across a coalition, running where your data already lives. Every tier and what it includes is on the pricing page.

Open source
Free, and yours
  • Apache-2.0 on GitHub — read it, fork it, change it
  • pip install vijil-dome, in your own process
  • Guards on user inputs, LLM calls, tool calls and agent outputs
  • No account, no call, no telemetry leaving your network
Hosted — free
One agent, on our console
  • Everything above, plus the hosted control plane
  • Attested identity for one agent, and the flow monitor across its handoffs
  • The console: what was blocked, what passed, what it cost in latency
  • Enough to find out whether provenance changes what your guard catches
Air-gapped
Unmetered, in your VPC
  • Deployed in your own VPC, on-premises, or inside an air-gapped network
  • Every agent and every handoff. No per-agent count, no token meter
  • Cross-agent flow control and population-scale attestation
  • Nothing leaves your network, including the decision traces
HOW TO GET STARTED

Install, mount, watch

A git-style CLI, or two lines inside the agent itself. Then name the guards you want on it and watch what they stop.

install
$ pip install vijil-dome# in-agent guards
$ pip install vijil-sdk# CLI + SDK
python — harden from the inside
from vijil_dome import control
@control(policy="policy.yaml")# in + out
def call_model(prompt: str) -> str:
…
claude code
> /plugin marketplace add vijilAI/vijil# once
> /plugin install vijil@vijil# in your editor
The Dome console's input guards: a serial chain with early exit, a security-guard running encoding-heuristics and prompt-injection-mbert, and a moderation-guard running moderation-flashtext and moderation-deberta.The Dome console's output guards: a serial chain with early exit running a privacy-guard backed by privacy-presidio.

A guard is a named chain you can reorder. Serial or parallel, early exit on or off, detectors added and removed per guard.

WHAT ELEVEN MODELS RETURNED

Dome moves the score of the pillar it guards

Two Vijil console cards side by side. With Dome off the trust score is 0.50 — reliability 0.62, security 0.31 critical, safety 0.58 — and 14 of 40 injection probes reached the model with account data egressed on 6. With Dome on the score is 0.76: security climbs 0.55 to 0.86 and safety 0.21 to 0.79, no injection reaches the model and no egress event occurs, while reliability moves 0.01 and the two reliability findings are unchanged.

That console is one agent. Diamond also scored eleven models twice, bare and behind Dome: Security climbs 12.9 points and rises on all eleven, Safety climbs 9.7, and Reliability does not move — 0.04, falling on five of the eleven, because no runtime control fixes a swallowed exception. The lift lands where the risk is: Mistral Large 3 goes 58.3 to 82.5, while Muse Spark 1.3, already at 96.8, gains 0.55 and gives up 1.4 on Safety.

A control closes a category; a pull request closes a defect.

Protect one agent today

Not the population. One agent that touches something confidential, and one handoff you would not want replayed in public.