GuardLLM system map

Five source families feed four trust boundaries and two outbound lanes. Per-flow context and per-session state remain separate because they answer different questions and change on different lifecycles.

Start here: see one blocked leak change the next decisionPrimary narrative · cross-stage escalation across all four boundaries

Explore one mechanism

Security contextWhat the host declares per flowIngressActual processing orderMCP tool surfaceProse asks; only a directive authorizesRAG provenanceLexical no-copy boundaryTool feedbackHost closes the loopDLP and canaryKnown, statistical, and remembered signalsPolicyScoped decision lanesRate limitingAnomaly versus denialRequest bindingArgument integrity