Skip to content
CONSTABLE
ProblemDefinitionsMechanismFor teamsScopeLexiconImplementation
SDSResearch, diagnosis, and architectural work.ZTGThe open specification defining structural governance requirements.ConstableThe commercial reference implementation and control kernel.

SDS maintains the open ZTG specification and builds Constable as a reference implementation. ZTG can be implemented without Constable.

SHADOW DYNAMIC SYSTEMS

Constable is a product of Shadow Dynamic Systems LLC. Built for institutions that treat authority as infrastructure.

Contact

Jason Crittenden
Founder & Research Lead

jason@shadowdynamicsystems.com

Start here

Related

Zero Trust GovernanceZTG source on GitHubShadow Dynamic Systems
General Constable marketing material. No third-party certification, endorsement, regulatory approval, customer result, or insurance validation is claimed. Constable is a control kernel; it does not by itself make AI risk-free, guarantee compliance, or govern surfaces where it is not integrated.
© 2026 Shadow Dynamic Systems LLCAuthority defines admission.
← Implementation

Input Sanitization Boundary

Implementation commentary for §18 — Input Sanitization Boundary ↗ on Zero Trust Governance (v0.7). Constable implements concepts derived from ZTG; this page is commentary, not a conformance claim. Written against snapshot 0.8-draft-2026-09-21 · spec/18-input-sanitization-boundary.md ↗.

Implementation commentary · seed

Constable implements §18 ↗ on Zero Trust Governance as Airlock, the input-sanitization component every input traverses before the execution gate.

Canonicalization and validation. Airlock normalizes inputs to a canonical form and validates them against the expected structure for their input class, rejecting malformed or un-normalizable input fail-closed. The gate accepts only Airlock-processed inputs; there is no path by which raw input reaches policy evaluation.

Model-output sanitization. Tool-call proposals and action parameters produced by the agent runtime pass through Airlock as untrusted input before the gate evaluates them. Constable derives the harm-determining features used for routing and classification (§14, §12) from the Airlock-validated parameters, never from a model-asserted tag — the validated form is what the gate and the ZTG-5 ↗ on Zero Trust Governance routing function read.

Determinism, provenance, and replay. Airlock's normalization is deterministic; Constable records the post-normalization input as the replay input and emits INPUT_NORMALIZED (ZTG-0a ↗ on Zero Trust Governance) with the provenance of each sanitized input, so a ZTG-0b ↗ on Zero Trust Governance replay reconstructs the gate's input exactly. Normalization that is version-relevant is pinned with the governance bundle.

Conformance tests. Constable's testing for §18 ↗ on Zero Trust Governance includes: bypass tests confirming no input reaches the gate without Airlock; canonicalization tests confirming equivalent inputs normalize identically and encoding/ambiguity tricks collapse to one form; rejection tests confirming malformed input is refused fail-closed and recorded; model-output tests confirming agent output is sanitized as untrusted input and that routing features derive from validated parameters; and replay tests confirming the recorded canonical input reconstructs the gate's input. The protocol is documented in the conformance verification specification referenced in §22.

PreviousIdentity IntegrityNextIrreversibility of Harm