Skip to main content
EMILIA Gate / local deployment / private alpha

Put the consequence firewall where the credentials live.

Your agent can propose the work. EMILIA Host keeps the provider credential beside Gate and checks the customer's exact authority before an activated covered HTTP or MCP action can enter the provider path.

In the Host deployment pattern, the agent never receives the provider credential. No accepted authority and required evidence, no covered provider entry.

Current surface: HTTP local service alpha, HTTP and MCP SDK protection, and governed pilots.

Credential boundaryPrivate alpha
AgentPOST /vendor/changeNo provider credential
EMILIA HOSTGATE INSIDE
01 Freeze exact action
02 Verify customer authority
03 Reserve before provider entry
EMILIA_AUTHORITY_REQUIREDor one admitted attempt
Credential-owning adapterProvider / system of recordEntered only after Gate admits the exact action
  • LOCALRuns beside the credential
  • EXACTChecks action-bound authority
  • CLOSEDRefuses missing or mismatched authority
  • BOUNDEDOnly activated covered paths
The security gap

The agent's credential can outlive the decision that justified its work.

IAM can show which workload has access. A prompt filter can flag suspicious text. Neither establishes that this exact bank-detail change, production deploy, data export, or permission grant fits the owner's finite mandate now.

Host is an AI agent firewall at the consequence boundary. It is not a prompt or model classifier. It verifies exact customer authority at the credential-owning provider boundary, immediately before the covered adapter can act.

One local crossing

The request is easy to understand. The boundary is hard to fake.

Host keeps proposal, authority, provider entry, and reported outcome separate. That makes refusal useful and prevents a successful API response from being mislabeled as proof of an external effect.

  1. 01
    Agent proposes

    HTTP request or MCP tool call, without the provider credential.

  2. 02
    Host freezes

    The exact action and activated deployment binding are fixed before asynchronous checks.

  3. 03
    Gate decides

    Customer-pinned authority and required evidence either fit this action or they do not.

  4. 04
    One provider attempt may enter

    Only an admitted operation can reach the credential-owning provider path.

  5. 05
    Outcome stays honest

    Refused, returned, or indeterminate are recorded without inventing effect certainty.

State means something

A refusal is not an execution. A response is not proof of effect.

REFUSED

No accepted authority

Host returns a structured challenge or refusal before the covered provider adapter is entered.

Provider entry: no
ADMITTED

Exact authority accepted

Gate reserves the accepted authority, then permits one covered provider attempt for that operation.

Provider success: not implied
INDETERMINATE

Provider outcome unknown

The authority remains consumed and blind retry stays closed until authenticated, action-bound reconciliation.

External effect: unresolved
What exists now

Start with the boundary you actually own.

Host is the local deployment form of EMILIA Gate, not a new protocol or a sixth product. A governed pilot begins with one consequence path and the credential that makes it real.

Choose the first boundary

HTTP local service alpha

Private alpha

HTTP over an owner-permissioned Unix socket for one governed local boundary. It is not a general HTTP reverse proxy; only the Host-side adapter holds the provider credential.

HTTP and MCP SDK protection

Private alpha

Wrap a credential-owning handler or MCP tool so exact request fields are frozen and checked before the real executor is entered.

Governed pilots

Available to scope

Customer-reviewed activation, bounded action coverage, explicit bypass review, durable state, and deployment evidence for one selected consequence path.

The honest boundary

Host protects what the customer actually routes through it.

Host's prevention claim is limited to activated covered paths. It does not establish complete mediation. It does not prove the external effect occurred, constrain alternate credentials, or make the action wise, legal, or correct.

Host events are not Consequence Ledger reconciliation. Host does not reconcile the Consequence Ledger, and Scan does not automatically activate Host. Customer review, signed authority, deployment pinning, durable state, provider profiles, and bypass removal remain part of the governed deployment.

Questions buyers ask

Before you put it beside a real credential.

These answers describe the current private alpha and governed-pilot boundary.

What is EMILIA Host?

EMILIA Host is the private, local deployment form of EMILIA Gate. It places Gate beside the credentials and adapters that can enter a provider path, then requires exact customer authority for each activated covered action.

Is EMILIA Host an AI agent firewall?

It is a consequence firewall for AI agents, but it is not a prompt or model classifier. Host verifies exact customer authority at the credential-owning provider boundary. It does not score whether a prompt looks risky.

Does Host protect every action on a machine?

No. The prevention claim applies only to activated covered paths that must pass through Host. Alternate credentials, direct provider calls, and unmediated executors remain outside the boundary until they are separately removed or mediated.

What happens when authority is missing or the provider result is uncertain?

Before provider entry, missing or mismatched authority returns a structured refusal such as EMILIA_AUTHORITY_REQUIRED. If provider entry occurred but the outcome cannot be established, Host records INDETERMINATE and refuses blind retry until authenticated reconciliation.

Can Scan configure Host automatically?

No. Scan can propose visible action boundaries and blind spots. The customer must review that proposal, define the authority, and approve the activated Host deployment. Scan does not automatically activate Host.

One consequence path first

Bring the action. Keep the credential. Install the boundary.

We will scope one activated HTTP or MCP path, the authority it must require, the bypasses that must be removed, and the evidence the customer needs to retain.