> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# AEGIS

> Adaptive Enforcement, Governance & Intelligence Substrate — the runtime screening layer of Safe House. Checks every gateway call at four checkpoints, under three per-agent settings, each set to one of four enforcement modes.

**Mnemom AEGIS** — Adaptive Enforcement, Governance & Intelligence Substrate — is the runtime screening layer of [Safe House](/concepts/safe-house). Every model call routed through the Mnemom gateway is checked at four checkpoints (front door, inside.autonomy, inside.integrity, back door). For each agent you choose, per setting, whether a check is `off`, only records (`observe`), warns (`nudge`), or steps in (`enforce`).

Detection content reaches the gateways as [Managed Rules](/concepts/managed-rules): an Ed25519-signed rule set that each gateway verifies before it uses it, and picks up within minutes of a change.

## The four checkpoints

A checkpoint is a *position* in the request lifecycle, not a per-turn budget. The front door fires once per inbound surface: a request that hands three tool results back to the model passes the front door for the message and again for each of those results. See [When the front door runs](/concepts/safe-house#when-the-front-door-runs).

| Checkpoint | Position | What it checks |
| - | - | - |
| **Front door** | Inbound: the newest user message, and each tool result in the request (enforce and nudge: before the model reads it; observe: in the background, after the request is forwarded) | Prompt injection, hidden instructions in tool results, social engineering, payment-change fraud, false claims of system or admin authority |
| **Inside.autonomy** | Mid-transaction | The tools offered to the model, against the agent's [Alignment Card](/concepts/alignment-cards); the tool calls the model makes, against the assets and operations your organization marks as protected |
| **Inside.integrity** | Mid-transaction | The agent's reasoning, reviewed by [AIP](/protocols/aip/specification) for prompt injection, value misalignment, autonomy violations, corrupted or deceptive reasoning, and undeclared intent |
| **Back door** | Outbound | Sensitive data in the response: card numbers, SSNs, API keys, private keys, access tokens, connection strings, emails, phone numbers and IP addresses. Redacted on non-streaming responses; recorded on streamed ones |

## Three settings per agent

| Setting | Covers |
| - | - |
| **Safe House** ([Protection Card](/concepts/protection-card) `mode`) | Front door, tool calls and back door. Each surface (incoming messages, tool responses, tool calls, outgoing responses) can be switched on or off. |
| **Autonomy** (`autonomy_mode`) | Tool use against the Alignment Card. |
| **Integrity** (`integrity_mode`) | The agent's reasoning. |

Settings apply at the platform, organization, team and agent level, and the strictest one wins. A lower level can add protection but cannot remove or weaken one set above it. See [Card Composition](/concepts/card-composition).

## Four enforcement modes

| Mode | What happens |
| - | - |
| **`off`** | The check does not run. |
| **`observe`** | The check runs and the result is recorded. The request and response are unchanged. |
| **`nudge`** | The request goes through with a warning the model and your application can see. Sensitive data in outgoing responses is redacted. |
| **`enforce`** | Flagged content does not go through. An unsafe message is replaced with a quarantine notice, a forbidden tool turn or a failed integrity check is replaced with a refusal, and sensitive data is redacted. The HTTP response itself is a normal response. |

Every gateway response carries the outcome of each checkpoint in the `X-Mnemom-Verdict` header, for example `front=pass; autonomy=pass; integrity=pass; back=pass`. See [Headers](/api-reference/headers).

## How detection rules are kept current

* **Signed delivery.** Managed Rules reach every gateway as an Ed25519-signed rule set. Each gateway checks the signature before it uses the rules and picks up changes within minutes.
* **Review before production.** New rules are reviewed before they reach production. See [Managed Rules](/concepts/managed-rules).
* **Continuous testing.** Screening is tested continuously by an automated, adaptive attacker that runs against sandbox agents in an isolated environment, never against customer agents.
* **Customer reports.** You can report a missed attack or a false block against a rule. Reports go into the review queue.

Every candidate rule carries a `writer_identity` recording where it came from (a customer's own false-negative or false-positive report, an internal observation, a security-researcher submission, or a platform-admin entry). It is stamped server-side from the auth context used at write time; a customer can file a report but never sets the writer identity itself.

## Limits

1. **Not a trust protocol.** AAP declares an agent's identity and alignment, AIP verifies reasoning in flight, CLPI governs the card lifecycle, and AEGIS screens traffic at the gateway. None of these layers substitutes for the others.
2. **Detection confidence varies by threat class.** A low-confidence rule in `observe` is not the same claim as a reviewed rule in `enforce`.
3. **Only traffic through the gateway is screened.** Direct provider calls that bypass the gateway are not seen.
4. **No supply-chain detection.** The [substrate fingerprint](/concepts/substrate-fingerprint) records which provider, model, SDK and (optionally) lockfile produced each checkpoint, as evidence for your own audits. AEGIS does not detect compromised dependencies; use package-level provenance for that. See [Supply-chain trust](/guides/supply-chain-trust).

## See also

* [Managed Rules](/concepts/managed-rules) — the signed rule set AEGIS publishes to every gateway
* [Safe House](/concepts/safe-house) — the per-customer screening configuration
* [Protection Card](/concepts/protection-card) — per-agent Safe House settings
* [Substrate fingerprint](/concepts/substrate-fingerprint) — what each checkpoint records about the stack that produced it
* [CLPI](/concepts/clpi) — the governance layer that composes with AEGIS
* [AIP specification](/protocols/aip/specification) — the per-turn integrity protocol


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.