Security Coverage Matrix

Protection applied and threats mitigated at each pipeline stage.

The following table shows the protection applied at each stage of the agent pipeline and the threat each control is designed to mitigate.

Pipeline StepProtection AppliedThreat Mitigated
InputDiscovery and TokenizationSecret/PII in prompts
ReasoningGuardrails monitoringPrompt injection
Tool CallsIntent validation and AuthenticationUnauthorized actions
Cross-AgentRe-tokenizationData leakage between agents
OutputPII scanning and Re-protectSensitive data in responses
LogsAnonymizationIdentity exposure in debug
StorageTokenizationPII at rest
ContinuousSemantic GuardrailsPolicy violations, anomalies

Last modified : July 21, 2026