OpenAPA brings deterministic prompt-injection defense to AI agents
OpenAPA applies a military-style data classification model to AI agents: a session inherits the highest classification level of the data it reads, and any attempt to write to a lower-trust destination is blocked by policy rather than by prompting. The approach is prompt-independent but lowers end-to-end completion rates and raises token costs.
- Agent session inherits the highest classification level of data it reads
- Writes to lower-trust destinations are blocked deterministically
- Defense is prompt-independent and resists prompt injection
- Trade-offs: lower completion rate and higher token usage
Read next
Security