AgentRiskLayer

Trust model

The LLM is not the security authority.

ARL separates orchestration from security authority so explanations cannot silently become findings, evidence or deployment decisions.

Authority model

Five clear responsibilities.

AIorchestration

ARLsecurity authority

Evidenceproof

Control Intelligencereadiness

Humanaccountability

Evidence chain

What can support readiness

Declared controlsCustomer statements remain declared until supported.
Observed controlsReviewable behaviour or system records.
FindingsAuthoritative ARL security findings.
Attack evidenceResults from bounded authorised tests.
Runtime evidenceRecorded control behaviour where applicable.
Human approvalExplicit accountable approvals when required.
RemediationImplementation evidence for the changed system.
RetestExact verification against the affected control.
Deployment decisionThe final accountable decision remains human.

Production-readiness requirement

Readiness must come from authoritative controls and evidence, not static website copy or a billing state. See System status for the public service-status route.

Unknown evidence remains unknown. A report is not an accredited certification, guarantee, insurance product or legal opinion.