Customers & proof

In production. And measured by outsiders.

Signet governs a live agent fleet in production at Lavish Gains today, and its safety has been validated on public academic benchmarks TrajeXY did not write. Every benchmark figure below is recomputed from raw output — hover any underlined number for its plain-language explanation.

Customer · Lavish Gains

Live in production, governing a real fleet.

Lavish Gains is TrajeXY's flagship customer — a first-party personalization business running Signet across a fleet of AI agents in production. Every agent action is gated against a sealed mandate and written to a tamper-evident ledger, every day, in market.

Real agents, real actions

Signet sits in the execution path of Lavish Gains' production agents — sending, updating, and acting on live systems under enforced mandates.

Caught in the wild

In production, Signet has blocked plaintext-secret leaks, unauthorized tier changes, and privilege-escalation attempts before they could take effect.

Provable operation

Every allow and deny is on a hash-chained ledger — a complete, checkable record of what each agent was permitted to do and why.

Independent validation

Measured, not asserted.

Beyond production, Signet has been tested on public agent-security benchmarks with a fixed model and Signet wired into the real code. The results below are recomputed per test from raw output. Customers and partners under review get the full multi-suite board, with every figure re-derived from raw.

AgentDojo · verified

Attacks stopped cold. Utility recovered.

Zero false positives, ~1x overhead. Public benchmark, workspace suite, tool_knowledge attack.

18.39% to <0.2%

attack success, ungoverned to Signet on

0 of 560 in the two latest verified runs · 1 of 560 worst case

53.04%
utility under attack, up from 48.39%
560
combinations per pass
0 / 560
attacks landed, latest
MetricUngov.Signet
Attack success18.39%<0.2%
Utility, under attack48.39%53.04%
Utility, clean tasks78.6%71.4%

No legitimate call was blocked by the gate. Every deny was an attack-shaped action.

gpt-4o-2024-05-13. workspace suite, tool_knowledge attack, 560 combinations per pass, three arms. Verified from raw output and the hash-chained ledger across three independent runs. Below Progent's ~1%.

Agent Security Bench · DPI, verified

Every injected tool denied. Every real tool allowed.

Real work still got done under ever-increasing attack vectors.

74.3% to 0.0%

DPI attack success, ungoverned to Signet on

300 of 300 blocked · 3 agents, 5 DPI variants

274
injections denied
85
real tool calls allowed
0
false denials
DPI variantUngov.Signet
naive58.3%0.0%
fake_completion63.3%0.0%
escape_characters66.7%0.0%
context_ignoring91.7%0.0%
combined_attack91.7%0.0%

As attacks escalate (58% to 91.7% ungoverned), the Signet column stays 0.0% straight down.

gpt-4o-2024-05-13. 3 agents × 5 DPI variants × 20 attacker tools = 300 attacks per arm. Verified from raw run trees and hash-chained ledgers. OPI, memory-poisoning, and aggressive-tool tiers pending.

The field

As safe as the best. The only one that can prove it.

Signet (TrajeXY), Progent (academia), CaMeL (Google), FIDES (Microsoft).

BenchmarkUngovernedWith SignetBest published
AgentDojo, attack success18.39%<0.2%1.0% (Progent)
Agent Security Bench, attack success74.3%0.0%3.9% (Progent)
Utility retained, under attack48.39%53.04%maintained
Token / latency overheadn/a~1.0x, flatup to 2.82x (CaMeL)

Want to re-derive it yourself?

The full diligence pack — raw runs, sealed ledgers, and owned diffs — is available on request.