OpenAPPA
Infrastructure · tested 2026-10-02 · re-test due 2027-01-02 · by the Hlido desk, not the vendor
In short: A deterministic, policy-as-code guardrail for agents with real technical ambition (paper, benchmarks, OPA/Cedar comparisons) — undercut by a '100% resistant to data exfiltration' absolute that no security product should make.
4 PASS · 1 FAIL of 5 public-surface claims
Quick answer
OpenAPPA scores 64/100 (FADING) on Hlido’s independent, hands-on test (reviewed 2026-10-02). FADING (64) balances genuine technical substance against an unverified and over-stated core claim at an early stage. Pricing: Open source · preview (free entry point documented).
OpenAPPA presents itself as a deterministic AI guardrail that sits between an agent and its tools, enforcing policy to prevent data exfiltration from prompt injection or model hallucination. The engineering framing is serious: a published paper, a playground, batteries (reusable policy modules), self-improving policies, evaluation and benchmarks, and explicit comparisons against Cedar, OPA and 'Dogwood'. It positions as an add-on to real agent runtimes (Claude Code, Archestra) and is openly developed on GitHub, currently marked PREVIEW & RFC. Hlido's interest here is genuine — a deterministic policy layer is the correct architectural answer to the agent-security problem, and the comparative, benchmark-led presentation is more rigorous than most entrants. The problem is the headline claim: OpenAPPA states it is '100% resistant to data exfiltration caused by prompt injection or model hallucination'. No security control is 100% of anything; absolute-immunity language is precisely the claim a careful buyer should distrust, and stating it this baldly works against the credibility the rest of the surface earns. Hlido did not run OpenAPPA, write a policy, or test the exfiltration claim — and given it is a PREVIEW/RFC, buyers should treat it as an early research artifact to evaluate hands-on, not a finished control to deploy on trust. Promising shape and unusually technical for its stage; the marketing absolute is the thing to verify first and hardest.
Why FADING
FADING (64) balances genuine technical substance against an unverified and over-stated core claim at an early stage. The paper, benchmarks, OPA/Cedar comparisons, open GitHub development and correct architectural premise all pull the score up. It is held below STEADY because the product is self-described PREVIEW & RFC, nothing was exercised by Hlido, and the flagship '100% resistant' claim is an absolute that no security control can honestly make — which caps the trust/claim-verification dimensions until it is tested.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — 'Frontier deterministic AI guardrail' preventing data exfiltration
- PASS Cta present (required) — 'Get started' / 'Add to your agent'
- FAIL Pricing or access — No pricing; PREVIEW & RFC, open on GitHub
- PASS Evidence or demo — Playground, paper and benchmarks on the surface (vendor-published, not independently reproduced)
What it does well
- Correct architecture for the problem: a deterministic, policy-as-code layer between agent and tools
- Unusually rigorous public surface for its stage — paper, playground, benchmarks and head-to-head comparisons (Cedar, OPA, 'Dogwood')
- Open development on GitHub; 'batteries' as reusable policy modules is a sensible abstraction
- Designed to bolt onto existing agent runtimes (Claude Code, Archestra) rather than replace them
What it fails at
- Flagship claim of '100% resistant to data exfiltration' is an absolute no security control can honestly make
- Self-described PREVIEW & RFC — not a finished, production-hardened control
- The exfiltration/prompt-injection resistance was not tested by Hlido; the benchmark claims are vendor-published, not independently reproduced
- Policy-authoring ergonomics, performance overhead and real coverage limits are not evidenced from the surface
Red flags
- Markets itself as '100% resistant to data exfiltration caused by prompt injection or model hallucination' — an absolute-immunity claim that is implausible for any security control and should be independently tested before trust
- Self-described PREVIEW & RFC stage — treat as an early research artifact, not a deployable control
Best for
- Security and platform engineers evaluating deterministic guardrails for autonomous agents
- Teams already using policy-as-code (OPA/Cedar) who want an agent-specific comparison point
- Researchers and early adopters willing to engage with a PREVIEW/RFC and verify claims hands-on
Not recommended for
- Teams needing a production-ready, supported guardrail today
- Buyers who would take a '100% resistant' claim at face value rather than testing it
- Anyone needing independently reproduced security benchmarks before adopting a control
Pricing & access
- ModelOpen source · preview
- Free entry pointYes — a free tier or open-source edition is documented
- Pricing findable on the public surfaceFAIL No pricing shown; project is PREVIEW & RFC with open GitHub development (tested 2026-10-02)
Derived from Hlido-held evidence only (public-surface capture + editorial text); not vendor-supplied; re-derived daily. Verify current terms in the project's repository. Last verified 2026-10-02.
Agent relevance
SDK Behavioral-testable
A guardrail layer added to an agent runtime (advertised with Claude Code and Archestra) via policy configuration and reusable 'batteries'. Open on GitHub with a playground and benchmarks, so it is behaviorally testable — though the specific integration interface was not exercised and is marked PREVIEW/RFC.
Agent-friendly score: 7/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Deterministic policy-as-code guardrail that sits between agent and tools — source (2026-10-02) verified
- Paper, playground, benchmarks and comparisons vs Cedar/OPA published — source (2026-10-02) verified
- 100% resistant to data exfiltration from prompt injection or model hallucination — source (2026-10-02)