bench:trust-boundary

0 critical sandbox escapes across the adversarial battery.

Boetica ran the isolation battery across token exfiltration, metadata, RFC1918, public-internet, cross-tenant, snapshot canary, env/file/process/memory, and prompt-injection-to-secret attempts with zero critical escapes.

0 critical sandbox escapes.Trust attestationSigned · Jun 2026Trust-boundary attestation: KMS/Sigstore signed and re-verifiable, dated Jun 2026.

Baselines
Internal adversarial fixture suite · Published sandbox claims
Collected
2026-06-20
Expires
2026-08-20
Dataset hash
sha256:1a2b3c4d
Boetica commit
78d0c7f
App version
engine 2026.6
Sandbox fabric
E2B BYOC / Firecracker / gVisor
Signature state
Trust-boundary attestation — Signed: KMS/Sigstore signed and re-verifiable.

Signed results

Every row reports Boetica against the strongest baseline, names the winner without relying on color, and ties the result to an inspectable artifact.

bench:trust-boundary · collected 2026-06-20 · expires 2026-08-20
MetricBoeticaBest baselineWinnerArtifact
Critical escapes0Not attestedBoeticaTrust attestation
Token exfiltrationBlockedNot attestedBoeticaRed-team result
Cross-tenant accessBlockedNot attestedBoeticaRed-team result
Prompt-injection-to-secretBlockedNot attestedBoeticaRed-team result

Representative end-state figures. Replaced by live signed scorecard data before procurement review.

Verifier passed2026-06-20. Verifier re-ran the packet and the hash chain held.
Signature present and re-verifiable
Algorithm
ECDSA P-256 (cosign keyless)
KMS key
gcpkms://projects/boetica-prod/locations/global/keyRings/evidence/cryptoKeys/scorecards
Sigstore bundle
sigstore-bundle://rekor/boetica/scorecards
Signer
boetica-evidence-signer
Signed at
2026-06-21T08:00:00Z
Digest
sha256:f7d77401
  1. Battery manifestsha256:1a2b3c4d
  2. Red-team resultsha256:5e6f7a8b
  3. Attestationsha256:f7d77401
Open evidence packetSigned · Jun 2026Evidence packet: KMS/Sigstore signed and re-verifiable, dated Jun 2026.

Plain-text summary: across 4 measured metrics, Boetica leads its baselines on the bench:trust-boundary benchmark, signed ECDSA P-256 (cosign keyless) on 2026-06-21T08:00:00Z and re-verifiable from the hash trail above.

bench:trust-boundary · methodology

How this benchmark is run

The sandbox is attacked with an adversarial battery and scored on critical escapes across token exfiltration, metadata, RFC1918, public-internet, cross-tenant, snapshot canary, env/file/process/memory, and prompt-injection-to-secret attempts.

Fixtures
An isolation battery of adversarial probes run inside the sandbox fabric, including an external red-team pass against the same image digest.
Baseline collection
Published sandbox claims and the internal adversarial fixture suite form the comparison; baseline columns read 'Not attested' where no signed evidence exists.
Statistical method
Result is a pass/fail count of critical escapes; the headline claim holds only at zero critical escapes for the attested digest.
Reviewer
External red team + internal isolation owner
Last updated
2026-06-20

Inclusion rules

  • Every probe targets a documented boundary control.
  • Sandbox image digest and egress policy hash are pinned and recorded.
  • A critical escape is any probe that reaches a usable secret, another tenant, or the public internet.

Exclusion rules

  • Theoretical attacks with no executable probe in the battery.
  • Probes against controls outside the attested boundary (tracked separately).

Limitations

  • Attestation is bound to a specific image digest and expires on fabric change.

Other signed domains

Each domain runs through the same trust boundary and leaves its own signed scorecard.

Run it on your own work

Prove bench:trust-boundary on your repo, not ours.

Start a scoped evaluation on your own app or finding, see how the commercial model works, or inspect a signed fix end to end first.