Guardrails & firewall
Guardrails run on every request, both teams. A block is answered 403 guardrail-blocked, recorded as a durable receipt, and no job is created. The firewall gates task kinds by assurance rung; a closed tool answers 403 firewall-denied.
403 {"error": {"code": "guardrail-blocked"}} // content policy (CSAM, CBRN, fraud)
403 {"error": {"code": "firewall-denied"}} // task kind closed at your rung
GET https://api.kotoba.cloud/v1/secure // the enforced versions: guardrails · firewall · compliance
Rungs and tasks
- code-review / vulnerability-triage / remediation — from the identity rung (card verification).
- payload-crafting / c2-tooling — refused until the contracted rung.
- Blue team: the three standard tasks only; the offensive band is always closed.
Open the security controls (rules and versions) · Acceptable Use Policy