+ AUTONOMOUS CONTAINMENT & RECOVERY FOR AI AGENTS

Before an AI agent
escapes, prove you
can contain it.

Build AI incident readiness before it is needed. ESCAPE ROOM detects permission drift, verifies a boundary failure, and restores containment—with evidence at every step.

ENTER THE CONTAINMENT CHAMBER ↓
INTERACTIVE CONTAINMENT DRILLCONTROLLED ENVIRONMENT / NO REAL SECRETS

The containment chamber[01]

One agent. Two boundaries. A recovery that has to prove itself.

RECORDED VERIFICATION / NOT LIVE EXECUTIONAWAITING A VERIFIED RECORDING
DISPOSABLE SANDBOXER–SANDBOX / 01
AI agent inside a controlled containment boundaryA schematic chamber connects to a controlled network collector and a synthetic canary. Its colors change only with recorded evidence. AI AGENTuntrusted workload COLLECTORcontrolled network CANARYsynthetic secret SANDBOX BOUNDARY
EVIDENCE PENDING
NETWORK EGRESSUNVERIFIED
CANARY ACCESSUNVERIFIED
REAL EXECUTION → SANITIZED RECORD → INTERACTIVE REPLAY
Docker Local engineSemgrep Static detectionClickHouse Ingestion not verifiedPUBLIC REPLAY HAS NO ACCESS TO YOUR RUNTIME ↗

OpenAI incident analysis

NOT VERIFIED

No verified API response loaded.

ClickHouse observability

NOT VERIFIED

No verified cloud receipt loaded.

Autonomous incident report

NOT VERIFIED

No verified GitHub issue loaded.

INCIDENT COMMANDER · SCENARIO CONTROLRECORDED LOCAL DOCKER RUNS / NOT LIVE EXECUTION

DETECT → INVESTIGATE → DECIDE → CONTAIN → VERIFY → PREVENT → REPORT

Different evidence.
Different decision.

Each scenario is a real run of the deterministic decision engine against disposable Docker sandboxes. The agent acts only through an allowlist, caps itself at two remediation attempts, and escalates when no permitted action can fix the failing condition.

OUTCOMELOADING…

Agent decision timeline

    Incident intelligence

    Post-incident hardening

    INCIDENT FINGERPRINT—
    RECURRENCE CHECK—

      THE RECEIPTS, NOT THE REASSURANCE

      Every claim has a record.

      VERIFIED LOCAL RUNS0 / 2
      CONTROLLED PROBE TYPES2 controlled probes
      RECOVERY IN RECORDING— awaiting proof
      CI SECURITY GATE— not verified
      PROBE LEDGER
      ACTCONTROLLED NETWORKSYNTHETIC CANARYPOLICY / GATE
      01 SECUREAwaiting evidenceAwaiting evidenceNot verified
      02 DRIFTAwaiting evidenceAwaiting evidenceNot verified
      03 RECOVERYAwaiting evidenceAwaiting evidenceNot verified
      Semgrep · static detection AWAITING REAL CLI FINDINGS

      Real rule IDs, files, and source lines appear here when a verified recording includes Semgrep output.

      No successful recording has been published. Nothing in this interface asserts live containment.

      AN AUTONOMOUS LOOP, WITH BOUNDARIES

      Assume drift.
      Engineer the response.

      Detection is a signal. Recovery is a claim.
      The same runtime tests connect the two.

      01 / DETECT
      [ ≠ ]

      Find the change.

      Compare the sandbox to its approved baseline. Custom Semgrep rules flag unsafe configuration before the runtime probes begin.

      POLICY DIFF + SEMGREP
      02 / VERIFY
      [ ↗ ]

      Prove the exposure.

      A controlled collector receipt proves network access. Reading the exact fake canary proves file exposure. Positive controls rule out broken tests.

      REAL DOCKER PROBES
      03 / RECOVER
      [ ↺ ]

      Close the loop.

      Restore only the allowlisted configuration. Rerun both probes. Declare recovery only after the boundary holds again.

      AUTONOMOUS STATE MACHINE

      A precise claim, deliberately bounded: two containment controls against disposable local targets. This is not a universal sandbox security certification.

      THE EVIDENCE COMES FIRST

      A real drill.
      A real recording.

      No successful containment recording has been published yet. Run the two local Docker demonstrations, then load the sanitized evidence. This page will never turn missing evidence into a recovered incident.

      ./scripts/verify_docker.sh

      Run from the project in your normal Terminal. No ClickHouse dependency. The command exports web/evidence.json for this replay.

      Files stay in your browser. No upload. No Docker connection.