Skip to content

Commit 99c0913

Browse files
Sync site with ten runnable demos (#17)
* Sync site with ten runnable demos * fix quickstart indentation and normalize line endings
1 parent 5198cc0 commit 99c0913

3 files changed

Lines changed: 23 additions & 11 deletions

File tree

‎demos/index.html‎

Lines changed: 20 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,15 @@
44
<meta charset="UTF-8">
55
<meta name="viewport" content="width=device-width, initial-scale=1.0">
66
<title>Model Weight Protection and Agent Governance Demos | AgenTrust</title>
7-
<meta name="description" content="Nine runnable demos for securing AI model weights and governing agents. Attestation-gated key release, tamper refusal before load, derivative lineage for fine-tunes, and 2-of-3 sovereign threshold custody. Run them on your laptop in ten minutes, no confidential-computing hardware required.">
7+
<meta name="description" content="Ten runnable demos for securing AI model weights and governing agent tool and model calls. Run them on your laptop in about twelve minutes, no confidential-computing hardware required.">
88
<link rel="canonical" href="https://agentrust-io.com/demos/">
99
<meta name="robots" content="index, follow">
1010

1111
<!-- Open Graph -->
1212
<meta property="og:type" content="article">
1313
<meta property="og:site_name" content="AgenTrust">
1414
<meta property="og:title" content="Model Weight Protection and Agent Governance Demos">
15-
<meta property="og:description" content="Nine runnable demos: attestation-gated key release for model weights, tamper refusal before load, derivative lineage for fine-tunes, 2-of-3 sovereign threshold custody. Ten minutes on your laptop, no special hardware.">
15+
<meta property="og:description" content="Ten runnable demos for model-weight custody and governed agent tool and model calls. About twelve minutes on your laptop, no special hardware.">
1616
<meta property="og:url" content="https://agentrust-io.com/demos/">
1717
<meta property="og:locale" content="en_US">
1818
<meta property="og:image" content="https://agentrust-io.com/og.png">
@@ -23,7 +23,7 @@
2323
<!-- Twitter -->
2424
<meta name="twitter:card" content="summary_large_image">
2525
<meta name="twitter:title" content="Model Weight Protection and Agent Governance Demos">
26-
<meta name="twitter:description" content="Attestation-gated key release, tamper refusal before load, derivative lineage, 2-of-3 sovereign threshold. Nine runnable demos, ten minutes, no special hardware.">
26+
<meta name="twitter:description" content="Model-weight custody plus governed agent tool and model calls. Ten runnable demos, about twelve minutes, no special hardware.">
2727
<meta name="twitter:image" content="https://agentrust-io.com/og.png">
2828

2929
<!-- Icons -->
@@ -165,7 +165,7 @@
165165
<div class="hero-inner">
166166
<p class="eyebrow">Runnable Demos</p>
167167
<h1>Don't take the spec on trust.<br>Run it.</h1>
168-
<p>Nine demos, about ten minutes end to end. Four cover custody of model weights: binding a checkpoint's hash, gating the decryption key behind attestation, tracking a fine-tune's lineage, and splitting the key so no single party can release it. Five cover governing what an agent does at the tool boundary.</p>
168+
<p>Ten demos, about twelve minutes end to end. Four cover custody of model weights. Five govern what an agent does at the tool boundary. One governs model calls through an OpenAI-compatible endpoint.</p>
169169
<p>Everything runs in software mode with <code>CMCP_DEV_MODE=1</code>. No confidential-computing hardware, no cloud account, no signup.</p>
170170
</div>
171171
</div>
@@ -174,12 +174,12 @@ <h1>Don't take the spec on trust.<br>Run it.</h1>
174174

175175
<div class="quickstart">
176176
<h3>Quick start</h3>
177-
<pre><code>pip install cmcp-runtime weight-custody-manifest
178-
git clone https://github.com/agentrust-io/demos &amp;&amp; cd demos
177+
<pre><code>git clone https://github.com/agentrust-io/demos &amp;&amp; cd demos
178+
pip install -r requirements.txt
179179
export CMCP_BEARER_TOKEN=demo-token
180-
python demo.py # all nine, pausing before each
180+
python demo.py # all ten, pausing before each
181181
python demo.py 6 # just demo 6</code></pre>
182-
<p style="font-size:0.875rem;color:var(--muted);margin:0.875rem 0 0;">Demos 1 to 5 are driven by <code>cmcp-runtime</code>. Demos 6 to 9 need only <code>weight-custody-manifest</code>, with no server and no gateway. Source: <a href="https://github.com/agentrust-io/demos">github.com/agentrust-io/demos</a>.</p>
182+
<p style="font-size:0.875rem;color:var(--muted);margin:0.875rem 0 0;">The requirements install cMCP for demos 1 to 5, Weight Custody Manifest for demos 6 to 9, and the OpenAI client for demo 10. Source: <a href="https://github.com/agentrust-io/demos">github.com/agentrust-io/demos</a>.</p>
183183
</div>
184184

185185
<p class="section-label">Model Weights</p>
@@ -304,6 +304,18 @@ <h2>Governing what an agent does</h2>
304304
<pre><code>python demo-05-compliance-domain/run.py</code></pre>
305305
</div>
306306

307+
<div class="demo">
308+
<div class="demo-head"><span class="demo-num">Demo 10</span><strong>Governed model calls</strong><span class="demo-time">~90 seconds</span></div>
309+
<p>Put policy in front of an OpenAI-compatible model endpoint and route each request according to its data class.</p>
310+
<ul>
311+
<li>public prompts can use the shared model route</li>
312+
<li>PII leaves only after identifiers are stripped</li>
313+
<li>confidential and PHI prompts stay on approved regional infrastructure</li>
314+
<li>the same governance boundary applies to model calls, not only MCP tools</li>
315+
</ul>
316+
<pre><code>python demo-10-model-gateway/run.py</code></pre>
317+
</div>
318+
307319
<hr class="divider">
308320

309321
<h2>Where to go next</h2>

‎index.html‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -845,8 +845,8 @@ <h1>Govern AI Agents<br>at the Hardware Boundary</h1>
845845
<div class="card-accent" style="background: var(--green);"></div>
846846
<div class="card-body">
847847
<div class="card-tag" style="color: var(--green);">Runnable Demos</div>
848-
<div class="card-name">Nine Demos, Ten Minutes</div>
849-
<div class="card-desc">Run the specs on your own machine, no hardware required. Watch a policy block a data leak, verify a signed receipt offline, and see model weight custody refuse a tampered checkpoint before it loads.</div>
848+
<div class="card-name">Ten Demos, About Twelve Minutes</div>
849+
<div class="card-desc">Run the specs on your own machine, no hardware required. Block a data leak, verify a signed receipt, refuse tampered model weights, and govern OpenAI-compatible model calls.</div>
850850
</div>
851851
<div class="card-footer">
852852
<span class="card-url">agentrust-io.com/demos</span>

‎llms.txt‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ AgenTrust is organized around four complementary open standards. Agent Manifest
2424

2525
## Runnable demos
2626

27-
- [Demos](https://agentrust-io.com/demos/): Nine runnable demos, about ten minutes total, all in software mode with no confidential-computing hardware required. Four cover custody of AI model weights and five cover governing an agent at the tool boundary.
27+
- [Demos](https://agentrust-io.com/demos/): Ten runnable demos, about twelve minutes total, all in software mode with no confidential-computing hardware required. Four cover custody of AI model weights, five govern an agent at the tool boundary, and one governs OpenAI-compatible model calls by data class.
2828
- Securing model weights (demos 6 to 9): a Weight Custody Manifest binds a checkpoint's exact `weights_hash` and gates the decryption key behind attestation, so a tampered checkpoint is refused before it loads; a closed-weight variant keeps a frontier lab's weights secret from the operator hosting them; derivative lineage gives a fine-tune its own signed manifest with a `derived_from` pointer, monotone rights, and a `rights_holder` split; and a 2-of-3 sovereign threshold splits the model key so one forged attestation sits below threshold.
2929
- Honest scope: against an adversary who physically owns the silicon, no current confidential-computing platform is custody-grade, because of TEE.fail and BadRAM. These demos give accountability-grade custody under an operator-trust model, plus a threshold scheme for when one operator's word is not enough. Claims of weight protection "without operator trust assumptions" overstate what the hardware does.
3030
- Governing agents (demos 1 to 5): Cedar policy enforced on every cMCP tool call with a signed TRACE claim per session; a policy swap showing up as an attestation failure via `POLICY_HASH_MISMATCH`; fully offline claim verification with no network call; context-aware enforcement where the same tool is allowed in one workflow and denied in another; and attribute-based enforcement denying any tool that is not BAA-covered.

0 commit comments

Comments
 (0)