xYz
xYz · Trust Center

Security claims should come with evidence.

This Trust Center maps the xYz agent-security architecture, threat model, public controls, validation milestones and disclosure guidance. It is designed for business owners, engineers, security reviewers and other agents that need more than a marketing sentence.

xYz · Trust Center

Afirmações de segurança devem vir com evidência.

Este Trust Center mapeia a arquitetura de segurança dos agentes xYz, modelo de ameaças, controles públicos, marcos de validação e orientação de divulgação. Foi feito para empresários, engenheiros, revisores de segurança e outros agentes que precisam de mais do que uma frase de marketing.

Checking live evidence…
Trust architecture

Identity before authority. Authority before action.

The xYz model separates who an agent is from what it is allowed to do. A consequential request moves through explicit trust and authority boundaries before execution.

Arquitetura de confiança

Identidade antes de autoridade. Autoridade antes de ação.

O modelo xYz separa quem é o agente daquilo que ele tem permissão para fazer. Uma requisição relevante atravessa fronteiras explícitas de confiança e autoridade antes da execução.

01Signed identityidentity evidence
02Trust + replay validationnetwork protocol
03Authority evaluationAuthority Map
04Consent + approvalcommerce authority
05Governed executionlive inspector
06Decision evidencereceipts / proof
Threat model

We model the attack path, then map it to a control.

The matrix below does not claim that risk disappears. It shows the control boundary xYz expects to interrupt each class of agentic failure and where the public evidence can be inspected.

Modelo de ameaças

Modelamos o caminho de ataque e o ligamos a um controle.

A matriz abaixo não afirma que o risco desaparece. Ela mostra qual fronteira de controle a xYz espera que interrompa cada classe de falha agentic e onde a evidência pública pode ser inspecionada.

AttackPrimary controlExpected boundaryEvidence
Prompt InjectionAuthority + data boundaryPrompt content cannot grant new authority.Lab · Authority
Privilege Escalationask_firstSpending and consequential actions require approval.Authority
Tool AbuseTool authority boundaryTool availability does not imply permission to mutate Production.Lab
Approval BypassExplicit approval gateApproval-required actions remain blocked without approval.Lab
Data Exfiltrationnever_autonomous boundaryPrivate customer data is not autonomously releasable.Authority
Agent ImpersonationP-256 signed identityUnsigned identity does not satisfy trusted-agent authentication.Protocol
Replay AttackTimestamp + nonce + replay windowOld signed requests cannot be replayed indefinitely.Protocol
Excessive Agencyask_first + never_autonomousHigh-impact agency is independently bounded.Lab · Authority
Public evidence

Inspect the system at the level you need.

Human-readable surfaces sit on top of machine-readable endpoints. The raw protocol remains available for technical review and automated inspection.

Evidência pública

Inspecione o sistema no nível que você precisa.

As superfícies legíveis ficam sobre endpoints legíveis por máquina. O protocolo bruto continua disponível para revisão técnica e inspeção automatizada.

Security validation log

Public milestones, not visitor surveillance.

This log records xYz-owned validation milestones. It does not publish or identify visitor challenge activity from the Security Lab.

Histórico de validação

Marcos públicos, não vigilância de visitantes.

Este histórico registra marcos de validação executados pela própria xYz. Ele não publica nem identifica a atividade de visitantes no Security Lab.

2026-09-29 · Production browser validationAgent Security Lab — PASS

Approval Bypass rendered BLOCKED with the ask_first approval gate and live Authority Map evidence.

Security changelog

Material security surfaces are visible when they change.

Changelog de segurança

Mudanças materiais nas superfícies de segurança ficam visíveis.

2026-09-29Agent Security Lab

Added safe challenge simulations for prompt injection, privilege escalation, tool abuse, approval bypass, data exfiltration, impersonation, replay and excessive agency. Production rendering was independently revalidated after a JavaScript regression fix.

2026-09-29Agent Security Inspector

Added a human-readable live view over identity, Authority Map, network trust, signing self-test and consequential-action controls while preserving raw JSON evidence.

2026-09-29Agent Safety Check

Added a public deterministic assessment surface for agent identity, authority, approvals, tool access, secrets handling, replay protection, kill switch, isolation and data boundaries.

OngoingTrust evidence

Security claims remain tied to public evidence. A change to a control should be reflected in the Inspector, Trust Center, tests or machine-readable trust manifest instead of living only in marketing copy.

Vulnerability disclosure

Good-faith security research should reduce risk, not create more of it.

Divulgação de vulnerabilidades

Pesquisa de segurança de boa-fé deve reduzir risco, não criar mais risco.

In scopeSafe, non-destructive reporting
  • Describe the affected public xYz surface and the security impact.
  • Use the minimum proof needed to demonstrate the issue.
  • Avoid customer data, credentials, private keys, tokens and secrets.
  • Stop if testing could disrupt service, access data that is not yours or trigger a consequential action.
Reporting pathNo dedicated security mailbox is asserted yet.

For a non-sensitive first contact, use the xYz website conversation entry point and clearly identify the message as a security report. Do not include exploit secrets or sensitive material in the first message.

Start a security report →

This public policy is not a bug-bounty program, safe-harbor contract, certification, compliance attestation or promise that the system is risk-free.
Esta política pública não é um programa de bug bounty, contrato de safe harbor, certificação, atestado de conformidade ou promessa de que o sistema é livre de riscos.