Product updates

CapitalGuard release record.

Release notes for the license product, scanner workflow, AccessGraph, delivery vault, and commerce system.

MCP Integrity Gate 0.1

Signed tool inventories and output quarantine

July 18, 2026

Every approved MCP server is locked to one measured identity digest, protocol version, exact tool list, descriptions, input schemas, and output schemas.
Mutating and unknown tools require an already-verified one-time gateway approval; every request is reserved before invocation so sequential and concurrent replay fail closed.
Untrusted provider output is quarantined outside agent context by default, while public schemas, vectors, release digests, and residual boundaries make the control inspectable.

Agent Delegation Firewall 0.1

Single-use authority chains for multi-agent work

July 18, 2026

Every signed delegation binds one target agent, task, policy, root session, capability subset, expiry, and maximum chain depth.
A parent envelope can be spent on one child or one terminal request, never both; sequential and concurrent replay fail closed in a lock-protected local ledger.
Public schemas, synthetic signatures, threat model, support matrix, and release digests state the exact control and the live-adapter boundary.

Enforced Mode 0.3

Unified runtime trust chain for contained AI-agent sessions

July 19, 2026

The licensed launcher builds a policy-filtered read-only workspace and starts a digest-pinned OCI image without direct network, host-source, Docker-socket, or ambient-secret access.
Every dynamic request is task-bound, signed as model-originated context, derived as untrusted, checked against sequence history, and then evaluated by the default-deny gateway.
Separate Context Provenance and Runtime Sequence authorities, external security-state roots, and authenticated pending state make replay, rollback, and uncertain crash recovery fail closed.
The 22-case publisher-operated benchmark and signed open challenge publish the exact boundary, evidence, provenance, and limitations without unsupported competitor scores.

Agent Action Gateway 0.1

Routed operation enforcement with replay-protected approvals

July 16, 2026

The licensed gateway enforces supported file, command, and metadata-only network operations submitted through its local adapters.
Approval leases are signed, short-lived, bound to exact request and policy digests, and atomically limited to one use.
Every decision appends a privacy-safe tamper-evident event and states that operations bypassing the gateway remain outside its control.

Policy Language 0.1

Deterministic default-deny policy decisions

July 16, 2026

The licensed kit now includes a strict local evaluator for allow, redact, approval, simulation, and block decisions.
Public schemas, test vectors, stable control IDs, and a signed release manifest make the policy contract independently testable.
Every decision states that evaluation alone does not intercept runtime operations or prove enforcement.

AccessGraph 1.0

Action-to-asset exposure mapping and Guardprint drift

July 10, 2026

Licensed local scans now generate a CapitalGuard AccessGraph across read, change, execute, and transfer actions.
A SHA-256 Guardprint compares aggregate exposure state with the previous scan without placing source contents or secret values in the graph.
The customer kit now includes the AccessGraph standard, privacy boundary, control language, and responsible claim limits.

Prevention Playbooks 1.0

Package-specific prevention playbooks

July 7, 2026

Playbooks page now converts common AI-agent findings into implementation steps, evidence collection, and controls to install.
Builder exports customer-safe packets for secret exposure, prompt injection, workflow risk, and customer-data context.
Playbooks route is wired into navigation, footer discovery, demo library, docs, partner links, referral-safe routing, and sitemap coverage.

Guardrail Installer 1.0

Dedicated AI-agent guardrail installer page

July 7, 2026

The guardrail page packages the local installer as a customer-facing policy artifact with install command, policy template, and planner.
The planner generates a downloadable policy preview for repo profiles, declared deny paths, protected files, untrusted instruction sources, and approval gates.
The legacy route remains wired into navigation, footer discovery, demo library, partner links, referral-safe routing, and sitemap coverage.

Repo Scanner 1.0

Browser-side AI-agent exposure scanner

July 7, 2026

Public scanner now flags secret-like files, workflow risk, prompt-injection signals, agent configs, package lifecycle scripts, customer data, auth, billing, and log exposure.
Scanner generates a downloadable triage report with evidence, precautions, and a Starter, Pro, or Agency recommendation.
Scanner route is wired into navigation, footer discovery, demo library, partner links, referral-safe routing, and sitemap coverage.

License Console 1.0

Post-purchase service workflow

July 7, 2026

Public console now ties package scope, license readiness, scan inventory, service steps, and handoff packet generation together.
Customers can continue from the console into activation, authorized scan intake, customer-kit downloads, report viewing, policy generation, and verification.
Console route is wired into navigation, footer discovery, demo library, partner link building, referral-safe routing, and sitemap coverage.

Review Intake 1.0

Verified review and checklist conversion flow

July 7, 2026

Reviews page now includes customer-proof slots and a verification-first review packet builder.
Public checklist maps AI-agent repository control gaps to Starter, Pro, or Agency checkout paths.
Partner links and referral routing can send customers directly to the checklist page.

Proof Ledger 1.0

Public product evidence page

July 7, 2026

Proof ledger links product routes, package scope, product demos, downloadable scanner assets, and readiness evidence.
Claim boundaries explain authorization, redaction, badge review, and breach-prevention limits.
Partner referral links can now send qualified customers directly to the public proof page.

CapitalGuard Scanner 1.0

Three launch license flows

July 7, 2026

Starter, Pro, and Agency product pages explain scope before checkout.
Stripe checkout is environment-gated so incomplete production configuration cannot silently issue a license.
The readiness endpoint reports whether payment, fulfillment, database, and email requirements are configured.

Delivery Vault 1.0

Customer delivery and recovery flow

July 7, 2026

Customer vault centralizes activation, scan intake, customer kit, and access recovery.
Checkout remains closed while automatic backend secrets are not configured.
License and certificate flows are designed to avoid displaying raw secret values.

Commerce Layer 1.0

Productized license sales system

July 7, 2026

Homepage now includes product cards, proof metrics, comparison math, FAQ, and demo paths.
Affiliate program pages, tracked referral routes, and payout-policy copy are in place.
Source archive excludes local secrets, dependencies, build cache, and operator records.

Launch checkout

Starter, Pro, and Agency are ready.

Compare Licenses