trust spine · positioning
Compare — Project-AI vs the field
Source-scoped architecture distinctions against OPA, Anthropic Constitutional AI, Guardrails AI, and NVIDIA NeMo Guardrails. Categorical cells are frozen until claim-specific evidence review is complete.
sourcingComparison is architecture-level, drawn from each project's public documentation and written from a Project-AI perspective. It is not a benchmark, an endorsement, or a security audit of any other project. All cells remain
partial during the claim freeze; they do not establish absence, superiority, or exclusivity. Corrections welcome via /contact.property | Project-AI execution-governed | OPA policy engine | Constitutional AI Anthropic | Guardrails AI output validators | NeMo Guardrails NVIDIA |
|---|---|---|---|---|---|
| Enforcement model | |||||
Governance runs BEFORE execution Decision must precede side-effects, not annotate them after. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Deny-by-default Absence of an explicit allow = no execution. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Terminal execution verdict ontology Project-AI documents ALLOW · DENY · SAFE_HALT as terminal execution verdicts. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
| Audit | |||||
Hash-linked receipt design The normal portal server path hash-links and signs receipts; ledger-wide provenance is unverified. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Trust-root publication and external timestamping The portal declares one build key; offline verification and external timestamping are incomplete. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Version-pinned replay from receipt bundle A receipt contract, canonical bytes, and clean-clone fixtures are prerequisites. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
| Identity & capability | |||||
Capability tokens with AC0–AC5 tiering Authority class explicit, not implied by role string. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Identity attestation gate The architecture requires identity evidence before policy authorization. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
| Continuity | |||||
State continuity gate (STATE_REGISTER) SAFE_HALT on missed heart-tick, not silent retry. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
| Policy authoring | |||||
Policy artifact integrity Signed packaging and Code Store loading remain planned or unverified capabilities. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Declarative DSL with formal grammar | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
| Threat surface | |||||
Separates policy from the governed payload Policy is not in the model's context window. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Contains effects from a compromised model The architecture targets an external effect boundary; end-to-end bypass evidence is pending. | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
| Transparency | |||||
Open red-team scenarios with reviewed submissions | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
Anonymous public decision stream | claim status and evidence pending in /claims | not independently assessed here | not independently assessed here | not independently assessed here | not independently assessed here |
honest distinctions
- · OPA provides policy evaluation; enforcement depends on its integration.
- · Constitutional AI addresses model behavior and may be combined with effect controls.
- · Guardrails AI provides validation components whose placement is application-defined.
- · NeMo Guardrails provides conversational control components and integrations.
- · Project-AI documents a separate pre-effect governance target.
if you only remember one row
Keep state namespaces separate. Project-AI uses ALLOW · DENY · SAFE_HALT for terminal execution verdicts. Policy dispositions, gate outcomes, runtime health, and other projects' response types are different taxonomies and are not ranked by this page.
Related