# Security Architecture · PlainReal

Source: https://plainreal.com/security

Security architecture

## Built for the security review. Not just the sales conversation.

Every control claim on this page maps to a specific field in the record schema and a specific test in the write-storage-seal harness, which covers the commit sequence end to end. Hand this page to your security team.

Ed25519 FIPS 186-5 Signing

FIPS 140-3 Level 3 HSM (production)

RFC 3161 Trusted Timestamp

COMPLIANCE S3 Object Lock mode

33 Fields Schema v1.0.0

10/10 OWASP ASI Mapped

Security review

### OWASP Top 10 for Agentic Applications mapping.

All 10 risks mapped to specific record fields. Evidence Type distinguishes pre-execution prevention from post-execution recording. The controls exist in the architecture. This is not a marketing document.

ID OWASP Risk Evidence Type Controls What the artifact proves

ASI01 Agent goal hijack Prev + Record input_hash · substrate enforcement · AUTHORIZATION_INPUT_MISMATCH Input committed in signed token before execution. Substrate blocks if actual input differs. Artifact proves authorized vs presented input.

ASI02 Tool misuse and exploitation Prev + Record tool_call_log · authorization_token_id · action_type · BLOCK_ON_SERVICE_UNAVAILABLE Signed token declares action_type pre-execution. tool_call_log records every tool invoked. Comparison proves misuse.

ASI03 Identity and privilege abuse Recording principal_identity · signing_key_id · HSM signing Every artifact names the agent the substrate recorded as acting, inside the signed payload. Altering it breaks the signature.

ASI04 Agentic supply chain vulnerabilities Recording model_version_hash · registry_validation_status · sdk_binary_sha3 · rekor_log_id Exact model, SDK binary hash, Sigstore transparency log entry. Complete forensic supply chain traceability.

ASI05 Unexpected code execution Prev + Record action_type · tool_call_log · BLOCK_ON_SERVICE_UNAVAILABLE TIER-A token required before code execution. action_type and tool_call_log prove authorized vs actual execution.

ASI06 Memory and context poisoning Recording full_prompt_snapshot · rag_evidence_bundle · causality_chain_hash Complete prompt captured at call time. RAG sources recorded with provenance. Forensic examiner identifies poisoning across chain.

ASI07 Insecure inter-agent communication Recording causality_chain_hash · instrumentation_coverage Each hand-off commits the parent record’s hash, so an inserted or missing step is detectable afterwards. Uninstrumented agents in the chain are marked, not assumed. PlainReal does not secure the channel; it evidences the hand-off.

ASI08 Cascading failures Recording causality_chain_hash · instrumentation_coverage · RECORD_COMMIT_FAILED Hash-chained record of every step. Coverage records instrumented vs uninstrumented nodes. Failure patterns reconstructable.

ASI09 Human-agent trust exploitation Prev + Record policy_version_hash · availability_policy · CONFIGURABLE_BY_ACTION_TYPE Human approval tokens required for high-risk actions. Policy version bound to artifact proves governance in force at decision time.

ASI10 Rogue agents Recording deployment_mode · evidence_tier (TIER-A/B/C) · instrumentation_coverage Trust level per artifact. Uninstrumented nodes produce TIER-B boundary records flagging potential rogue paths.

n/a Insecure output handling OWASP LLM Top 10, not on the agentic list Recording output_pre_postprocess · execution_result Raw model output before and after filters. Delta is auditable. Insecure handling detectable from artifact.

Raw mapping on GitHub ↗
Zenodo DOI: 10.5281/zenodo.20486369 ↗

NIST SP 800-53 Rev 5

### Control mapping.

records address specific NIST SP 800-53 controls. The full mapping is published on GitHub alongside the OWASP mapping.

Control family Control How PlainReal™ addresses it

Audit and Accountability (AU) AU-2, AU-3, AU-9, AU-10 Non-repudiable, tamper-evident record of every consequential AI agent action. Ed25519 signature binds the artifact to the signing key.

Access Control (AC) AC-2, AC-3, AC-6 Authorization Token binds pre-execution approval to a specific action_type and principal_identity before the agent runs.

Identification and Authentication (IA) IA-2, IA-9 principal_identity + signing_key_id fields provide cryptographic proof of agent identity per artifact.

System and Information Integrity (SI) SI-7 SHA3-256 record_hash over the 32 signed fields. S3 Object Lock COMPLIANCE mode prevents post-commit modification.

Configuration Management (CM) CM-3, CM-5 policy_version_hash and model_version_hash bind the exact policy and model in force at decision time to the artifact.

Supply Chain Risk Management (SR) SR-4, SR-11 sdk_binary_sha3 and rekor_log_id provide Sigstore-anchored supply chain traceability for model and SDK.

Full SP 800-53 mapping on GitHub ↗
Zenodo DOI: 10.5281/zenodo.20486631 ↗

Citable references

OWASP Top 10 for Agentic Applications mapping doi.org/10.5281/zenodo.20486369 ↗

NIST SP 800-53 Rev 5 mapping doi.org/10.5281/zenodo.20486631 ↗

Both published on Zenodo. Apache 2.0. Permanent citable references for use in audit reports, regulatory submissions, and legal proceedings.

The architecture of the evidence

### Four pillars. Each tied to the architecture.

What makes a record hold up is the combination of these four properties. Each one is independently verifiable without PlainReal cooperation.

Pillar 01 · Cryptographic identity

Ed25519 signing

FIPS 186-5 algorithm · HSM-backed in production

Every record is signed inside PlainReal infrastructure. Signing today is in software, using Ed25519 (FIPS 186-5). Moving it into a FIPS 140-3 Level 3 HSM is a later phase, with the same algorithm and identical schema. The signature binds each artifact to a specific signing key and proves it could not have been produced by anyone else.

Pillar 02 · Storage integrity

S3 Object Lock COMPLIANCE

Customer-owned bucket · Per-artifact retention lock

Artifacts are written to your S3 bucket in COMPLIANCE mode, not GOVERNANCE. Once committed, the object cannot be modified or deleted by anyone, including PlainReal, the AWS account root, or your own administrators. This is what gives the record evidentiary integrity under examination.

Pillar 03 · Independent time

RFC 3161 timestamping

Neutral third-party TSA · Applied after WORM commit

After the WORM commit confirms, the artifact hash is timestamped by an independent RFC 3161 timestamp authority. Three parties hold pieces of the trust: you (the bucket), PlainReal (the signature), and the TSA (the timestamp). No single party can alter the record.

Pillar 04 · Continuous infrastructure

Evidence durability

Past artifacts independently verifiable · Continuous signing pipeline

Any past artifact is independently verifiable using only the published public key, for forensic moments and audit walkthroughs. The signing service, schema currency as regulations evolve, and the auditor reference base are the ongoing PlainReal layer that keeps producing new artifacts.

Independent verification

### The examiner verifies without calling us.

Every artifact is verifiable offline using the standalone CLI and the published public key. No PlainReal infrastructure required. No vendor cooperation required.

The public key confirms that PlainReal signed the artifact and that it has not been tampered with since. It does not provide access to decision content. The underlying data stays in your S3 bucket, under your own access controls. Possession of the public key by anyone outside your organization gives them nothing they could not already see if they had access to your bucket.

Verification element Where it lives What it proves

Public key fingerprint verify.plainreal.com/samples/demo_pubkey.pem The signing key used to produce the artifact. Verifiable against the artifact's signing_attestation field.

record_hash Artifact field, cryptographic hash Covers all non-signing fields. Any modification breaks the hash. Verifiable without PlainReal.

WORM confirmation S3 GetObjectRetention (per-artifact) lock_mode = COMPLIANCE and retain_until_date confirm the object cannot have been modified since commit.

RFC 3161 timestamp separate .tsr token Evidences that the artifact existed at the stated time, countersigned by a neutral timestamp authority. It is a separate file, not a field: the Ed25519 signature covers content, not time. Published sample records carry no token.

Verifier page integrity signed release tag on github.com/plainreal/verify Each release is a signed tag whose message names the SHA-256 of public/index.html . A hash published only inside the repository it describes would be circular, since whoever can edit one can edit the other; the signature is what ties those bytes to a key. Hash the page you were served and compare it against the tag to confirm you are running the release, not something substituted for it.

Independent verifier verify.plainreal.com · source Checks the signature and the record hash in your browser. It makes no network request and stores nothing, so you can read what it does before running it. No PlainReal account, and no PlainReal service involved.

Security review

### Questions for your security team?

Send the full OWASP mapping to your security architect. If they have questions we have not addressed here, we want to know.

Contact us ↗
