{
  "@context": "https://schema.org",
  "@type": "SoftwareApplication",
  "@id": "https://www.insightits.com/products/prism-shield.html",
  "slug": "prism-shield",
  "canonicalName": "Prism-Shield",
  "name": "Prism-Shield — Zero-Trust AI-to-DAG Execution Gateway",
  "canonicalUrl": "https://www.insightits.com/products/prism-shield.html",
  "knowledgeUrl": "https://www.insightits.com/catalog/prism-shield.json",
  "markdownUrl": "https://www.insightits.com/catalog/prism-shield.md",
  "family": "aiSecurity",
  "infraFamily": "AI Security",
  "recordType": "product",
  "status": "published",
  "parentProduct": null,
  "whatItIs": "Runtime zero-trust gateway between agent extractions and enterprise DAGs. Canonicalize → policy/schema → seal ParameterManifest → KMS-attest → ACCEPT / REVIEW / REFUSE. Apache-2.0 open core; depends prismmanifest>=0.3.4.",
  "problem": "Unvetted probabilistic output must not become deterministic side effects at runtime — CI (Prism-Eval) is not enough once the agent is live.",
  "isNot": [
    "Another agent framework",
    "PrismGuard",
    "SOC2-certified (control-mapped ≠ certified)",
    "Hosted HITL as the Stripe SKU (Coming for Team+)"
  ],
  "alternatives": [
    {
      "name": "Ungated agent → DAG execute",
      "relationship": "No published competitor bake-off. Companion to Prism-Eval (CI) and PrismManifest (library)."
    }
  ],
  "features": [
    {
      "name": "Fail-Closed Policy & Schema",
      "description": "Unknown policy_id or schema_hash refuses. Versioned policies and published schema hashes are allowlists, so the gateway never invents trust for an ID it has not seen."
    },
    {
      "name": "Sealed ParameterManifest + KMS Attestation",
      "description": "ACCEPT seals a FlatBuffer ParameterManifest signed through a KMS envelope backend (Azure Key Vault, AWS KMS, GCP, or local), enforced by the C++ gate when loaded, else the Python hard gate."
    },
    {
      "name": "ACCEPT / REVIEW / REFUSE",
      "description": "REVIEW seals a PASS_WITH_HUMAN manifest and queues an escalation for human review; REFUSE hard-blocks. Replay receipts stop a sealed decision being replayed into the DAG."
    }
  ],
  "architecture": "Fail-closed unknown policy_id / schema_hash. ACCEPT seals a FlatBuffer ParameterManifest signed through a KMS envelope (Azure Key Vault, AWS KMS, GCP, or local), enforced by the C++ gate when loaded, else the Python hard gate.",
  "useCases": [
    "LangGraph access-control middleware in front of money DAGs",
    "CrewAI runtime guardrails at execute time",
    "Human-in-the-loop REVIEW when policy requires it"
  ],
  "benchmarks": {
    "published": false,
    "summary": "No published vendor benchmark for this product. Do not invent metrics.",
    "disclosures": [
      "No published vendor benchmark for this product. Do not invent metrics."
    ],
    "urls": []
  },
  "github": "https://github.com/insightitsGit/Prism-Shield",
  "pypi": "https://pypi.org/project/prism-shield/0.2.1/",
  "documentation": [
    {
      "title": "Commercial terms",
      "url": "https://www.insightits.com/legal/prism-shield-commercial.html"
    },
    {
      "title": "Prism-Eval (CI companion)",
      "url": "https://www.insightits.com/products/prism-eval.html"
    },
    {
      "title": "Compose with VectorPrism / Manifest / Eval",
      "url": "https://www.insightits.com/products/prism-shield.html#compose"
    },
    {
      "title": "https://github.com/insightitsGit/Prism-Shield",
      "url": "https://github.com/insightitsGit/Prism-Shield"
    },
    {
      "title": "https://pypi.org/project/prism-shield/0.2.1/",
      "url": "https://pypi.org/project/prism-shield/0.2.1/"
    },
    {
      "title": "https://www.insightits.com/products/prismmanifest.html",
      "url": "https://www.insightits.com/products/prismmanifest.html"
    },
    {
      "title": "https://www.insightits.com/products/prismguard.html",
      "url": "https://www.insightits.com/products/prismguard.html"
    },
    {
      "title": "codespaces",
      "url": "https://codespaces.new/insightitsGit/Prism-Shield"
    }
  ],
  "install": "pip install prism-shield (pin ==0.2.1). Apache-2.0 open core; commercial SKU under EULA. Soft CTA SHIELD — mailto:info@insightits.com?subject=SHIELD.",
  "version": "0.2.1",
  "relatedProducts": [
    "prism-eval",
    "prismmanifest",
    "vectorprism-demo"
  ],
  "publisher": {
    "@type": "Organization",
    "name": "Insight IT Solutions",
    "legalName": "Insight IT Solutions LLC",
    "url": "https://www.insightits.com"
  }
}
