An information-flow policy engine for LLM agents
OpenAPPA is an open-source (MIT-licensed), deterministic information-flow policy engine for LLM agents. Instead of matching patterns or using LLM judges, it tracks data flows across tool calls using security labels (audience × trust), deriving every enforcement decision algebraically so prompt injection or model hallucination cannot cause data exfiltration. It runs outside the agent's prompt and execution loop and plugs into an existing agent loop in one place.
Policies describe data sources, audiences, trust levels, and authorities; every agent trajectory carries a security label that only ever gets more restrictive, and each decision is derived algebraically from it.
A single TOML configuration drives the cross-platform, pluggable engine, letting you validate in CI/CD that the whole tool graph is covered and scale to millions of agents without changing the config.
The engine runs outside the agent's prompt and execution loop, so the model cannot see, negotiate with, or manipulate it — 'you cannot prompt-inject an algebra.'
Instead of a bare 'forbidden' that stalls agents, blocked calls return a remedy plan describing legal ways to proceed, which the vendor says lifts task completion from 37% to 90% on their benchmarks.
Stock sanitizers ship in the box to mask secrets or redact PII so payloads can flow to wider audiences; custom sanitizers, including model-based ones, plug in with a clear blast radius.
A human or internal API can approve one specific action without lifting the session's restrictions for later calls.
Untrusted reads can be isolated in a disposable branch so the parent trajectory continues unpoisoned.
Includes validation, observability, reporting (appa yell), and self-improving policies; documentation is also available as an MCP server or via curl.
Every agent trajectory carries a security label of audience × trust: reading a private repo narrows the audience, reading an unvetted web page lowers trust. Labels only become more restrictive.
The engine derives each tool-call decision from the current label algebraically, rather than judging calls with a classifier or matching regexes.
The engine plugs into an existing agent loop in one place and runs outside the prompt/execution loop. It supports coding agents, LLM proxies, MCP gateways, MCP servers, and agents in production, with documented integrations for Archestra, Claude Code, and kAgent.
When a flow is blocked, the agent receives a machine-readable remedy plan — sanitize the payload, get an authority approval, or use a subagent — so it can legally proceed instead of stalling.
OpenAPPA is an information-flow policy engine for LLM agents — a deterministic AI guardrail designed to be 100% resistant to data exfiltration from prompt injection or model hallucination, without breaking agent task completion. It is open, vendor-agnostic, and MIT-licensed.
It doesn't use a second model to judge tool calls (which classifiers can't track data flow across calls and are themselves prompt-injectable), and it doesn't match patterns like blocked commands (which agents route around). Instead it tracks data flows with security labels and derives decisions algebraically.
A single appa.toml configuration describes data sources, audiences, trust levels, and authorities. Every trajectory carries a security label (audience × trust) that only gets more restrictive, and the engine derives each decision from that label.
OpenAPPA returns a machine-readable remedy plan when a flow is blocked: sanitizers (mask secrets, redact PII), authorities (approve one specific action via a human or internal API), and subagents (isolate untrusted reads in a disposable branch). The vendor reports this lifts task completion from 37% to 90% on their benchmarks.
Per the vendor's published benchmarks: OpenAPPA achieves 89% task completion with 0% successful attacks, compared to Claude Auto mode (90% / 10%) and FIDES by Microsoft (41% / 31%).
Yes, it is MIT-licensed, and the project is vendor-agnostic. Code and documentation are available on GitHub.
It plugs into an existing agent loop in one place and supports coding agents, LLM proxies, MCP gateways, MCP servers, and agents in production, with documented setup for Archestra, Claude Code, and kAgent.
Pricing is not stated on the website; the project is MIT-licensed open source.