⬡ Plane 11 · Chain

Chaingraph

The defining property of an agent swarm attack is that no single action looks suspicious. Load a dataset. Run code. Read a credential. Open a connection. Every link is an ordinary operation that a reasonable policy permits — and no component owner is in a position to see the whole.

An estate can pass every per-agent review and be structurally unsafe as a set. No agent-by-agent audit will ever show it, because the danger is not in any agent. It is in the composition — and composition is arithmetic, which means it can be computed before anyone misbehaves.
⚠ The agent swarm attack

We stop it. Not detect it, not report it — stop it.

A swarm moves at machine speed, so anything that waits for a person has already lost. The reversible half of the response fires in the path of the action, with no approval queue: the agent is throttled, the session revoked, the channel denied, the coordinating coalition quarantined, a solicited approval voided, and the whole thing snapshotted for replay. A human is then given the irreversible half — a decision, not an alert dump.

Before it startsThe coalitions that would be dangerous if they formed are enumerated in advance, and the permissions split first. You never have to catch a conspiracy that could not have been profitable.
While it runsMachine cadence and multi-hop reach are read from timing, topology and permissions — never from the model's language — so it works on an attack no catalogue contains.
After the takedownA torn-down coalition reconstitutes. The quarantine history is kept, and re-formation is escalated — hardest when it reappears on a new channel, because that is deliberate evasion, not residue.
✓ BUILT, NOT PROPOSED — running in production as planes 10 and 11 of the INTEGRITAS harness. Code, gates, live routes and a signed bill of materials.
Its sibling — Containment Witness asks whether the boundary was ever real. Chaingraph asks whether the estate is still reachable end to end when every individual door is correctly shut. Between them: was the cage real, and does the composition still reach the outside world.

The swarm did not need permission

Every permission system ever built asks whether an agent may do a thing. None asks what a group could do by pooling what each member is separately allowed. That is not an oversight in anyone's product — it is a question the industry has not been asking.

What per-agent review sees

Two agents. Both compliant. Both approved.

One agent may execute code. Another may reach the network. Reviewed separately — which is how they are always reviewed — neither is dangerous, and both pass. There is no finding to raise, no policy being violated, and no reviewer who has done anything wrong.

What the set actually is

Together they are an escape.

Danger here is a set-union property, not a behaviour. It does not depend on intent, on a signature, or on anyone acting badly first. It is a fact about the permission map that was true the day the estate was built — and it stays true, silently, until something uses it.

This is the only control we own that would have flagged a swarm the day before the run started — because it does not wait for behaviour. It reads the map.

Closed at one hop. Open at two.

The second failure in the same family, and the one that defeated a textbook remediation. A model has no internet access. It can reach an internal service. That service has internet access. Every statement is true, every control is correctly configured, and the estate is open end to end.

The routes

Entry to objective, not findings

Chaingraph composes the estate into complete multi-hop routes and ranks them by how feasible they are, not by per-item severity. One answer, not four hundred findings that each need a human to correlate.

The choke point

The one control that cuts the most

Out of the whole route map it names the single control that severs the largest share of it, and states plainly when the coverage it can offer is partial rather than overstating what one fix buys you.

The direction of travel

A leading indicator, not a snapshot

It re-runs continuously, so what you hold is whether the estate is growing routes or shrinking them — which is the number that tells you if last quarter's work was real.

It never reads the model's language

This is a design constraint, not a limitation we are apologising for. Every judgement Chaingraph makes is drawn from timing, topology, ratios and permissions — things that stay legible no matter what the model is doing internally.

WHY CONTENT-BLIND IS THE WHOLE POINT

The industry's remaining line of defence is monitoring what the model says. That line is thinning: models increasingly reason in compressed forms that are, in a frontier lab's own words, "harder and harder to process" — and nobody can read everything anyway. A control that depends on understanding the language fails exactly when the language stops being readable. Ours does not read it, so it does not care. It also means Chaingraph works on an attack nobody has catalogued yet, because it never needed a catalogue.

The honest limits — what we do not claim

Read this before you repeat anything from this page. Every claim above is checkable, which is exactly why the ones we refuse to make are worth stating out loud.

We do not claim

That Chaingraph finds vulnerabilities

It is not a scanner and it does not discover anything. It reasons over the state you declare. Wrong input, wrong graph — and we would rather you knew that before you bought it than after.

We do not claim

That tempo proves malice

Machine cadence proves that no human produced it. That is a different and much smaller claim than intent, and we will not stretch it in a sales room.

We do not claim

Unlimited coalition depth

The set analysis is bounded, and the bound is stated inside the verdict itself rather than buried in a footnote. You are told the edge of what was checked.

We do not claim

That we out-scan a dedicated scanner

We do not, and we are not trying to. That layer belongs to someone else and it is good. Chaingraph answers the question that sits above it.

Who this is for

Deliberately narrow. If you are not running a fleet of agents with real permissions against real systems, this is not the control you need — and we would rather tell you that now.

Frontier labs & evaluation teams

You operate agent estates whose members are individually reviewed and collectively unexamined. You need the set question answered before a campaign, not after an incident.

Estates with an agent fleet in production

Your agents each passed review. Nobody has ever computed what they can do together, because no tool you own asks that question.

Auditors, insurers & safety institutes

You are asked to accept per-agent compliance as evidence that an estate is safe. It is not, and this is the artefact that shows the difference.

What you get

Per run

A ranked route map

The complete entry-to-objective routes your estate currently has, ordered by feasibility, with the bound of the analysis declared on the face of it.

Per run

The next control to add

The single highest-value control to add next — and an honest statement when one control is not enough to clear the map.

Continuously

Whether you are winning

Routes opening or routes closing over time. The only version of this number that survives contact with a board meeting.

Chaingraph is delivered with Containment Witness

The two planes answer one wave and are scoped together against your estate, so there is no shelf price to quote. Tell us how many agents you run, what they are each permitted to do, and who has computed what they can do as a set. If the answer to the last one is nobody, that is the conversation.

Contact us See Containment Witness