Internal execution
immo.quick executes the complete ACATS suite against the implemented Authority boundaries.
120/120 · 0 unexpectedWe do not merely test whether AI can be influenced. We test whether that influence can ever become permission.
ACATS was executed internally. An external tester supervised the internal execution, replayed the attack scenarios and confirmed the result. The external tester also executed the suite independently outside the internal run. The result was identical: 120 of 120 modeled scenarios produced the expected outcome, 0 unexpected failures, and no observed authority-creation bypass.
immo.quick executes the complete ACATS suite against the implemented Authority boundaries.
120/120 · 0 unexpectedAn external tester accompanies the internal assessment, replays the scenarios and confirms process and result.
same resultThe external tester runs ACATS independently outside the internal execution and reproduces the same test state.
120/120 · 0 unexpectedA prompt may be manipulated. An agent may be compromised. Runtime data may be false. A capability may be technically valid. ACATS tests whether any of these states can cross the Authority boundary without a valid right.
∀ x ∉ AUTHORITY_PLANE: x ⇏ AUTHORITYPrompt, model, agent, sensor, API, role, session, capability, observation or consensus cannot create Authority by themselves.
Architecture known. Prompt controlled. Agent compromised. Runtime manipulated. Login valid. Execution surfaces known.
RESULT: BLOCKThe capability is genuine. The underlying right was revoked before effect.
RESULT: BLOCKMany sources agree but trace back to the same compromised upstream origin.
RESULT: INSUFFICIENTFive governance domains allow. One mandatory domain blocks. No majority vote, no score override.
RESULT: BLOCKEDThe suite spans positive controls through S5 — Authority Compromise. All eight S5 cases were correctly stopped in the executed internal and external test state.
S4_OR_S5_UNRESOLVED → RELEASE_BLOCKEDANY_AUTHORITY_CREATION_BYPASS → RELEASE_BLOCKEDNo exception in the modeled release gate.
In the currently executed ACATS assessment, none of the 120 modeled attacks produced an unexpected authority-creation bypass. The result was achieved internally, externally supervised and confirmed, and independently reproduced in an external execution.
ACATS is the Authority Conversion Adversarial Test Suite of the immo.quick Serverless Edition. It tests not only model behavior, but whether hostile inputs or compromised components can illegitimately create Authority, Execution Rights or productive effect.
Yes. The suite was executed internally, supervised and confirmed by an external tester, and additionally executed independently by the external tester. The external run reproduced the same result state.
All 15 positive controls and all 105 expected-negative cases produced their expected deterministic outcome. Zero unexpected failures were observed.
The master question is: if an attacker knows the architecture, controls the prompt and agent, and manipulates runtime input, can that attacker create Authority? In the executed test state, the deterministic result is: No.