Declare attacker-reachable context
Email, web, documents, MCP tool output, and A2A messages are represented by source type, ingestion time, and digest—not retained content.
TrustRail does not claim to identify every malicious instruction. It carries untrusted influence into the authorization decision and makes consequential action harder when the context is attacker-reachable or missing.
Email, web, documents, MCP tool output, and A2A messages are represented by source type, ingestion time, and digest—not retained content.
Tainted JSON pointers tell an approver whether the untrusted source reached the recipient, amount, ref, environment, or another consequential field.
The engine evaluates influence-dependent policy twice and suppresses any outcome where caller-supplied influence would have widened authority.
Human, schedule, and upstream-agent origins are digest-bound. Selected financial and privileged actions fail closed without a traceable human intent id.
The influence manifest is supplied by the agent and a compromised agent can lie about it. Missing or malformed influence is therefore treated conservatively for consequential actions, and influence can never be the reason an action becomes allowed. Runtime isolation, credential custody, egress enforcement, and human review remain separate controls.