Docs/Getting Started/Platform Overview & Architecture6 min read
GETTING STARTEDCore

Platform Overview & Architecture

Anchor is a sovereign, in-process runtime governance platform designed to prevent autonomous agent hallucinations, rogue API executions, and regulatory non-compliance before bytecode executes.

The AI Governance Gap

Traditional AI observability tools (Datadog LLM, LangSmith, Arize) operate purely post-hoc. They capture traces after execution has finished. If an autonomous agent triggers a fraudulent $500,000 settlement or exfiltrates confidential PII, an alert in a dashboard does nothing to prevent the damage.

Anchor changes the governance paradigm from passive post-hoc auditing to hard, synchronous, in-process runtime enforcement.

Every model tool call, database execution, and agentic parameter is intercepted within the running process memory, verified against compiled statutory invariants, and sealed into an append-only SHA-256 cryptographic chain before reaching production infrastructure.

Key Principle: Zero-Trust Runtime Boundary

Anchor treats all LLM outputs and agentic tool invocations as untrusted external user inputs. No code or API call generated by an autonomous system is permitted to execute without cryptographic and statutory verification.

Two-Tier Defense Model

Anchor enforces governance across two distinct layers of the software development and execution lifecycle:

LayerMechanismExecution PointLatency TargetPrimary Purpose
Layer 1: Static AST GatekeeperTree-sitter static analysis & .anchor lintingPre-commit & CI/CD Pipeline0 ms runtime overheadPrevents un-instrumented code & structural policy violations from reaching master branches.
Layer 2: In-Process InterceptorNative Rust C-ABI kernel & zero-copy memory buffersIn-Process Function Invocation< 15–350 microsecondsSynchronously intercepts arguments, validates risk boundaries, blocks rogue calls, and issues deterministic self-healing directives.
Decision Audit Chain (DAC)Append-only SHA-256 Merkle tree ledger with Ed25519 signaturesAsynchronous background queueNon-blocking (< 10 µs queue)Generates mathematically verifiable, tamper-evident audit dossiers for statutory subpoena readiness.

Deterministic Invariants vs Probabilistic LLM Judges

Why Anchor rejects LLM-as-a-Judge for mission-critical compliance.

Many legacy systems attempt to evaluate compliance by calling a secondary LLM (e.g. GPT-4) to judge if an agent's response was safe. This approach fails in institutional finance and healthcare for three fatal reasons:

1. Non-Determinism: An LLM judge can evaluate the exact same payload differently across attempts, violating fundamental legal predictability standards.

2. Latency Penalty: Remote LLM evaluations add 400ms to 2,500ms of network latency per agent step, destroying high-frequency performance.

3. Vulnerability to Jailbreaks: Secondary LLMs are susceptible to prompt injection and indirect goal manipulation.

Anchor compiles human laws (EU AI Act, RBI FREE-AI, SEC Reg SCI) into formal mathematical AST invariants and zero-copy Rust bytecode that executes deterministically in sub-millisecond time.

Threat Model & Trust Boundaries

The system provides mathematically proven guarantees against the following institutional threats:

Threat VectorAttack MechanismAnchor Mitigation
Goal Hijacking & Tool AbusePrompt injection forces agent to invoke unauthorized SQL delete or settlement APIs.Layer 2 @anchor.guard checks parameter types, maximum transaction caps, and allowed destination addresses against hard invariants.
Statutory Risk Ceiling BreachTrading algorithm exceeds maximum VaR or portfolio concentration during market volatility.In-process Rust engine intercepts risk ratio and returns BLOCKED_BY_ANCHOR with automated rebalancing directive.
Biometric & Emotion ProfilingCustomer support agent utilizes banned emotion classification models.EU AI Act Article 5 invariant halts execution and generates Critical Enforcement Notice.
Audit Log Tampering / RepudiationMalicious insider alters or deletes database logs after a rogue trading event.DAC SHA-256 parent hash chaining and Ed25519 signing ensure any alteration immediately invalidates the Merkle root hash.