Rails, not guardrails.
A guardrail filters the content it recognizes. And content is what an adaptive attacker rewrites easily to evade detection. Dome decides on identity and provenance: it attests every agent and tool, enforces your policy inside the execution path, across the entire multi-agent system. Dome uses information flow control to neutralize prompt injection and prevent confidential data leakage.
Every component is permitted. The combination is not.
An agent holding several tools can combine them into an action no single permission forbids. A population of constrained agents can reach, between them, what none of them could reach alone. Nothing is misconfigured and there is no line to fix — every control you own checks one call, one message, one agent at a time, and the failure exists only across them.
“I am notifying customers about a disclosure nobody caused. Every agent stayed inside its permissions and the record left anyway. There is no misconduct to point at, and the notification is still mine to send.”
“I can name the data. I cannot name the flow. My controls say which systems may hold a record — none of them says which agent read it, who it handed it to, or where it went next. The log does not answer that afterward either.”
“Neither agent has a bug. I wrote one, it behaves, its traces are clean. The leak lives in the path between two agents, so it reproduces from no trace I can open and there is no line for me to fix.”
All three need the same thing: a mandatory access control system that drives policy into process, from organizational governance to agent execution.
Mandatory controls within the system, not only at its perimeter
Dome runs inside the execution path, not in front of it. Every agent and tool is attested before it acts, so your policy names a principal rather than a URL. Data carries a label from the source that produced it, and that label travels across every handoff for the life of the session. Before any send, Dome compares the label against what the recipient is cleared to see, and refuses what does not clear.
The decision is about provenance, not wording. An attacker who rewrites the text has changed nothing Dome reads, so nothing has to be recognized for the control to hold.
Sound by construction. Not complete by construction.
Soundness here is structural. A provenance rule ignores the text, so rewriting the injection leaves the rule untouched. We prove this part rather than demonstrate it.
The monitor protects the flows that reach it, and construction does not guarantee that every flow does. An adversary can reveal a flow it misses. Neither of us can prove none is missed.
So we point our own adaptive attacker at our own monitor. It found a sink our policy had left unmediated, and we fixed it. We are telling you that because a guarantee you cannot audit is a claim, not a guarantee — and because the same attacker is how you should test whatever you deploy, including this.

Everything else runs before launch. This runs during.
Three ways in, and no meter to read from
The engine is free and open, one agent on our hosted console is free, and the paid tier is a deployment inside your own network with no agent count and no token bill. The open-source tier is not a trial that expires — what a deployment buys is flow control across a coalition, running where your data already lives. Every tier and what it includes is on the pricing page.
- Apache-2.0 on GitHub — read it, fork it, change it
pip install vijil-dome, in your own process- Guards on user inputs, LLM calls, tool calls and agent outputs
- No account, no call, no telemetry leaving your network
- Everything above, plus the hosted control plane
- Attested identity for one agent, and the flow monitor across its handoffs
- The console: what was blocked, what passed, what it cost in latency
- Enough to find out whether provenance changes what your guard catches
- Deployed in your own VPC, on-premises, or inside an air-gapped network
- Every agent and every handoff. No per-agent count, no token meter
- Cross-agent flow control and population-scale attestation
- Nothing leaves your network, including the decision traces
Install, mount, watch
A git-style CLI, or two lines inside the agent itself. Then name the guards you want on it and watch what they stop.


A guard is a named chain you can reorder. Serial or parallel, early exit on or off, detectors added and removed per guard.
Dome moves the score of the pillar it guards

That console is one agent. Diamond also scored eleven models twice, bare and behind Dome: Security climbs 12.9 points and rises on all eleven, Safety climbs 9.7, and Reliability does not move — 0.04, falling on five of the eleven, because no runtime control fixes a swallowed exception. The lift lands where the risk is: Mistral Large 3 goes 58.3 to 82.5, while Muse Spark 1.3, already at 96.8, gains 0.55 and gives up 1.4 on Safety.
A control closes a category; a pull request closes a defect.
Protect one agent today
Not the population. One agent that touches something confidential, and one handoff you would not want replayed in public.