sigma · wave 2 · controlled evidence
agσ

sigma

A policy-scoped behavioural decision layer — five-step escalation, deterministic verdicts.

Sigma reads what code is able to do — statically, pre-runtime — and resolves it to one auditable decision on a five-step escalation ladder: observe → shield → contain → quarantine → terminate. Calibrated for low false-positives: benign trees rest at observe, and only corroborated, high-confidence critical chains escalate to a hard fail.

evidence ledger

measured facts, not exposed machinery.

Decision profile from the 2026-05-17 low-false-positive calibration on a mixed developer workspace. Determinism verified by hermetic repeat-replay.

escalation ladder
observe → … → terminate · 5
benign baseline
resolves to observe · 0 false quarantine
fail-hard
terminate on confirmed invariant chain
escalation gate
corroborated, high-confidence evidence only
determinism
3/3 identical · tier/path/health/grade
verdict
structured JSON · milliseconds
blind-test precision
1.000 · TP 5 / FP 0 · shared scan_full pipeline
blind-test recall
0.208 · precision-favoured · 2026-05-08 corpus
SIEM export
webhook + Splunk HEC · structured verdict JSON
public layer

Low false-positive by design.

Benign developer trees rest at observe. Escalation requires corroborated, high-confidence evidence — raw signal counts never escalate on their own. Terminate stays reachable only for confirmed critical chains, and every decision carries an auditable trace of why it escalated.

gated layer

The mechanism.

Gate names, the trusted-source set, capability resolution and invariant mechanics, and formula identifiers stay sealed. Sensor coverage has known boundaries — characterised honestly and disclosed to evaluation partners under NDA, never advertised.

boundaries

what it is — and what it is not.

Public eval-kit is shadow mode — no contain, quarantine, or terminate on the open surface.

repository documents

standards & licenses.

Normative files, specs, and conformance guarantees from the official repository.

README.md
sigma · EVALUATION
agσ
sigma

A policy-scoped behavioural decision layer — escalation runtime.

  • 5-step escalation ladder: observe to terminate
  • Zero false quarantine on benign baseline
  • Verdict structured JSON in milliseconds
EVALUATION · RUNTIME
SPEC.md
sigma · specification

Protocol and mechanics normative reference.

§1
Escalation
5 levels
§2
Determinism
3/3 identical
§3
Latency
< 2.5 ms
§4
Output
JSON verdict
LICENSE
RESTRICTED
PROPRIETARY

Proprietary commercial license. Use, copying, or reverse engineering of the sealed engine core is strictly prohibited. Evaluators must sign the bilateral NDA.

PROPRIETARY