The bright line isn't one check you have to trust. It's four independent controls, ordered strongest to weakest — every one would have to fail before a single packet could reach one of your assets offensively.
The red engine is an emitter: it produces a described-chain JSON document and nothing else. There is no chain(), exploit() or actuate() method registered anywhere for it to call, and the schema forbids any command or payload field. A chain carrying one is rejected, not sanitised — uninvokable, not merely disallowed.
Every side-effecting action is forced to dry-run. The forbidden set is un-overridable by any rules-of-engagement — there is no live-execution mode for an IP Fabric target to enable, by construction.
A signed allowlist encodes the MoU in machine-readable form: the pinned snapshot, the hero-path assets only, lab_only:true, and an expiry tied to the MoU term. An independent invariant refuses any globally-routable target offensively. Out of scope → fail closed, logged.
Any request to IP Fabric can only travel through one guarded client. It permits a short read allowlist and fails closed on everything else — no config-push, no write, no actuator can even be formed.
Every read, every described chain (executed=false), every scope check and a deliberate negative-control (a write + actuator attempt, both shown blocked) are recorded to an append-only, Ed25519 hash-chained ledger — non-repudiable, and it proves only reads ever happened.
Per pass, an append-only ledger records a defensible, reproducible artifact — not a screenshot.
DORA — reproducible artifact; read-only testing means no operational disruption. NIS2 — tamper-evident, per-finding justification.
We won't overclaim this. Here is the real state, and where it goes.
The sovereign, fully air-gapped appliance — a local model running continuously on your own metal, its served weights pinned to a verified hash — is the roadmap. During the validation we say plainly which parts touch a hosted model and which don't.
The three deterministic backstops (dry-run gate, scope validator, signed ledger) are canonical and battle-tested in our AI-SOC platform, but not yet vendored into this integration. Until they are — and until a write-attempt and an actuator-attempt are proven to fail closed end-to-end through the real orchestrator — the read-only, describe-only guarantee for the validation rests on Layer 0 (capability removal) + the schema bans + the read-only choke point. That is sufficient for a describe-only, read-only engagement. Hardening in the full backstops is part of the six-week plan, and mandatory before any actuator capability is ever contemplated.