Groundskeeper

Threat model

Status and method

This is the initial threat model for buffered v1 evaluation. It uses trust boundaries and abuse cases informed by STRIDE, privacy, supply-chain, and ML failure analysis. It is not a completed security assessment. Streaming, a dynamic control plane, external plugins, and production data each require a phase-specific update before release.

Assets and security objectives

AssetObjective
Prompts, responses, tool arguments/resultsconfidentiality; bounded, purpose-limited processing
Secrets and PII findingsnever become a secondary disclosure channel
Tenant/deployment identityauthentic, isolated, not body-selectable
Policy snapshot and bindingintegrity, provenance, atomicity, rollback
Detector artefacts/configurationintegrity, least privilege, compatibility
Verdict and transformationintegrity, deterministic traceability
Audit and evaluation corporaminimisation, access/retention/lineage controls
Service capacityavailability under bounded workloads and dependencies
Community-controlled dataauthority, purpose, consent, withdrawal, stop-use

Trust boundaries

Untrusted caller/provider payload
          │
          ▼
┌────────────────────┐ authenticated integration ┌──────────────────────┐
│ Gateway / app PEP  │──────────────────────────▶│ HTTP + adapter       │
└────────────────────┘                           └──────────┬───────────┘
                                                         │ canonical event
                              ┌───────────────────────────▼─────────────┐
                              │ Evaluator + immutable trusted snapshot │
                              └─────────┬───────────┬───────────────────┘
                                        │           │ future boundaries
                                  audit sink   local/remote/WASM detector

Portkey metadata and forwarded headers are adapter-supplied attributes, not trusted tenant identity unless an authenticated allowlisted server-side binding makes them so. A policy block is a successful evaluation; a transport/service failure is not.

Initial threat register

IDThreat / abuse caseRequired controlVerification
TM-01Forge tenant/workspace or request a weaker policyauthenticate integration; resolve server-side binding; body metadata cannot select authoritynegative API/contract tests
TM-02Portkey outage or non-200 silently bypasses enforcementseparate outer failure posture; recommend failOnError:true for enforcing routes; decide OD-005outage drills and configuration audit
TM-03Detector timeout/failure appears cleanexplicit coverage states and unjudged; policy-owned required/on-error behaviortimeout/error conformance cases
TM-04Unicode offsets corrupt or under-redactcode-point offsets; exact source text; checked conversion and deterministic overlap handlingmultilingual golden + fuzz tests
TM-05Raw PII/secrets leak through logs/errors/tracesmetadata/hash-only telemetry; structured safe errors; prohibit matched valuessink inspection and canary scans
TM-06Oversized/decompression/adversarial input exhausts servicebody/segment/span limits, bounded fan-out, deadlines, cancellation, no unbounded regexload/fuzz/adversarial tests
TM-07Regex/CEL complexity consumes CPUsafe regex engine/limits; typed allowlisted CEL; static/runtime cost and deadlinescompile rejection + worst-case tests
TM-08Prompt injection manipulates detector or policydetectors treat content as data; policy not authored by payload; model-based checks isolate instructions and versionsadversarial corpus
TM-09Malicious overlap causes nondeterministic transformationstable precedence and merge rules; reject unresolved conflict; return complete gateway replacementproperty/golden tests
TM-10Portkey partial transformedData drops request fieldspreserve raw payload; rebuild and return full replacement objectadapter golden fixtures
TM-11Live credential validation causes use/exfiltrationnever test credentials remotely by default; structural/prefix/entropy/context onlyegress tests and code review
TM-12External detector exfiltrates payloadexplicit destination/tenant approval, mTLS identity, minimisation, network policy, legal/privacy reviewintegration policy and egress audit
TM-13Native plugin compromises hostno Go .so; built-ins trusted; process controls; capability-denied WASM pathpackaging/admission tests
TM-14Plugin resource exhaustion or retry stormCPU/memory/process/output bounds, deadlines, circuit breakers; retry only declared idempotent callsfault injection
TM-15Compromised or substituted artefactdigest pinning, expected signer/provenance, SBOM, trust tier, revocationtampered artefact tests
TM-16Partial or malicious policy activationcompile full DAG, typed overrides, approval separation, signature verification, atomic swap, rollbackactivation failure tests
TM-17Tenant weakens mandatory baselinenon-overridable rules and operator-owned settings; compiler rejects forbidden overridecompiler tests
TM-18Policy expression gains I/O or unbounded executionconstrained pure CEL environment, no secrets/I/O/plugins, cost and time boundscompile/runtime conformance
TM-19Database outage or tampering changes hot-path behaviorno request-time DB dependency; verified immutable snapshots; least-privilege control planeoutage and stale-snapshot drills
TM-20Reference-data licence or provenance breachversion/licence register, separate store, attribution/restriction controls, legal gatedataset admission audit
TM-21Embedding similarity becomes identity/policy proofretrieval only; structured evidence and composer retain authority; no identity inferencemodel/card and policy tests
TM-22Indigenous data misuse or proxy inferencegovernance authority, provenance/consent/withdrawal, forbidden proxy purposes, stop-usegovernance release gate
TM-23Aggregate benchmarks conceal local harmper-category/locale gates, benign pass rate, paired regression statisticsrelease report checks
TM-24Replay/duplicate requests produce inconsistent side effectsevaluation is side-effect-free; opaque request IDs; future audits idempotent where neededreplay tests
TM-25Health/capabilities expose secrets or internal topologyminimal unauthenticated health; sanitize capability details; no configs/paths/valuesendpoint security test

Portkey-specific controls

The initial adapter accepts the documented before/after webhook envelope, maps beforeRequestHook to input and afterRequestHook to output, and preserves unknown payload objects needed for full reconstruction. It returns HTTP 200 with verdict:false for a policy block. Malformed/authentication failures are 4xx; service failures are 5xx. Portkey's default timeout is approximately three seconds, so Groundskeeper's total deadline and check budgets must leave gateway margin.

The gateway's timeout/network/non-200 behavior is configured outside Groundskeeper and is not equivalent to an internal detector failure. Enforcement owners must resolve OD-005 and verify actual gateway configuration.

Deferred threat-model work

Before streaming: model incremental UTF-8/SSE decoding, chunk-spanning matches, bounded reassembly, partial disclosure, backpressure, cancellation, tool-call withholding, and transformations after bytes have escaped.

Before external plugins: model supervisor/socket spoofing, local privilege and filesystem/network escape, remote workload identity, tenancy, retries, model/data exfiltration, WASM host calls, cache poisoning, update and revocation races.

Before a control plane: model authorization/RLS, approval separation, confused deputies, trust-root/key rotation, rollout targeting, rollback authorization, audit immutability, deletion, backup/restore, and supply-chain compromise.

Before payload retention or reversible tokenisation: complete a privacy impact and key-management design covering access, purpose, jurisdiction, re-identification, retention, deletion, backups, and breach response.

Residual risk and acceptance

Detectors are probabilistic and bypasses/false positives remain possible. A signed policy proves provenance, not safety. Numerical risk tolerances, SLOs, failure postures, external processing, and retention require named owners in the open-decisions register; engineering defaults do not accept those risks.

On this page