Archestra has released OpenAPPA, an open-source security engine that enforces data-flow rules outside an AI agent’s prompt and execution loop. The goal is to prevent sensitive information from reaching an unauthorized destination even when prompt injection or a model error changes the agent’s behavior.
Administrators describe data sources, audiences, trust levels and authorities in a policy configuration. OpenAPPA then applies deterministic rules across tool calls. This differs from asking a second language model to approve each action: a model-based reviewer can be probabilistic, vulnerable to injection and unable to reconstruct data movement when some tool output is hidden from it.
Archestra reports zero successful attacks on Bench-Corp, which contains 20 multistep enterprise workflows, and on AgentThreatBench. In the company’s comparison, Claude Code’s auto mode allowed 10% of attacks and Microsoft FIDES allowed 31%.
Those figures are the developer’s benchmark results, not an independent guarantee of zero risk. A fixed policy can also block legitimate work if its categories or permissions are wrong. The release nevertheless offers a concrete security pattern: keep mandatory information-flow controls outside the agent that is being controlled, log the resulting decisions, and test the policy against both attacks and valid workflows before production use.