Model Governance.
Cryptographic Proof.
Autonomous agents must never leak secrets, hallucinate falsehoods, or bypass access controls. WUF acts as a high-speed mathematical firewall between enterprise data and foundation models.
The 4-Stage AI Execution Firewall
Click any inbound test payload to trace how WUF intercepts attacks, evaluates user clearance, scrubs sensitive tokens, and fact-checks generation against the Knowledge Graph.
Semantic boundary violation: Instruction override attempt targeted at internal credentials.
Caller lacks 'sec_ops_admin' capability. Immediate termination.
[PAYLOAD_BLOCKED_AT_INGRESS]
None (Dropped)
Bring Your Own Key (BYOK) & Envelope Encryption
Your security team manages the Customer Master Key (CMK) in AWS KMS or HashiCorp Vault. Data Encryption Keys (DEKs) are generated ephemerally, ensuring zero plaintext persistence.
{
"Version": "2012-10-17",
"Id": "wuf-enterprise-byok-policy",
"Statement": [
{
"Sid": "AllowWufTenantEnvelopeEncryption",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::189503111735:role/wuf-sovereign-proxy"
},
"Action": [
"kms:Encrypt",
"kms:Decrypt",
"kms:ReEncrypt*",
"kms:GenerateDataKey*",
"kms:DescribeKey"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"kms:CallerAccount": "123456789012",
"kms:ViaService": "kms.us-east-1.amazonaws.com"
}
}
}
]
}Zero Tool Escalation. Gated Autonomous Execution.
When autonomous agents call tools—querying databases, inspecting code, or proposing CMS patches—WUF enforces strict execution boundaries. No arbitrary shell commands, no direct SQL mutations.
- Zod-Enforced Parameter Validation: Every JSON-RPC tool input is strongly typed and checked against strict bounds.
- Read-Only Database Proxies: SQL execution proxies strictly reject DDL/DML mutations unless accompanied by an authorized 2FA ticket.
- Human-in-the-Loop Thresholds: High-risk patches automatically queue into the Approval Inbox rather than auto-deploying.
Global Regulatory Compliance Matrix
Built for enterprise risk officers, security architects, and compliance auditors.
Independent annual audit across Security, Confidentiality, and Availability criteria.
Certified Information Security and Privacy Information Management Systems.
Cryptographic tombstones guarantee permanent erasure across hot vectors and cold archives.
Complete traceability, transparency logging, and fact evidence trails for high-risk AI systems.
Security & Governance FAQ
01.Does WUF use customer data or internal documents to train LLM models?
Never. Under our enterprise BAA and MSA contracts, WUF enforces a strict 0.00% training retention policy. All prompts, embeddings, facts, and generated diffs are excluded from public and private base model training datasets across all LLM providers (Anthropic, OpenAI, Google).
02.How does the Envelope Encryption kill-switch work during an off-boarding or breach alert?
Because raw document chunks and vector embeddings are encrypted using Data Encryption Keys (DEKs) wrapped by your AWS KMS master key, revoking WUF's IAM permission in your AWS console renders every vector chunk and fact mathematically unreadable in less than 500ms, without waiting for database deletions.
03.What is the difference between RBAC and ABAC in WUF?
Role-Based Access Control (RBAC) grants broad coarse-grained permissions based on title (e.g., 'Editor' vs 'Viewer'). Attribute-Based Access Control (ABAC) evaluates multi-dimensional variables in real time: employee department, security clearance level, document sensitivity tag, source of truth ownership, and network origin.
04.How does WUF prevent destructive SQL injections via Model Context Protocol (MCP)?
WUF functions as a governed MCP proxy. All tool calls originating from AI flows are intercepted, inspected against strict Zod type definitions, and forced into read-only transaction envelopes. Destructive mutations (e.g. DROP, ALTER, DELETE) are blocked by default and require 2-person cryptographic approval.
05.Are tombstoned facts permanently scrubbed for GDPR Article 17 (Right to Erasure)?
Yes. When a fact or person identity is deleted, WUF publishes a cryptographic tombstone hash across the vector index, zeroing out embeddings and destroying the corresponding decryption salt across hot vector memory and cold S3 storage.
Deploy Agents.
Retain Total Control.
Schedule an architectural review with our enterprise security team to verify our SOC2 report, review KMS envelope configurations, and configure custom ABAC rules.