ZTDS.ai Open AI Security Standard
Automated Pre-Audit Tooling · Invariant 1 Egress Verification

ZTDS Perimeter Network Scanner

Empirical zero-trust verification. Monitor active browser sockets, audit pipeline code against RFC v1.0 invariants, simulate hardware airplane isolation, and generate verifiable cryptographic audit receipts.

WAN Egress
0.00 Bytes
Invariant 1 Verified
Socket Boundary
Air-Gapped RAM
No Cloud DLP Hop
In-RAM Latency
< 0.20 ms
OSF Latency Tested
Airplane Mode
100% Offline
Zero Network Req
MODE 0: LIVE DOMAIN PERIMETER & ARCHITECTURE AUDITOR

One-Scan Domain Perimeter & ZTDS Blueprint Generator

Inspect any external web application, SaaS, or API endpoint. Identifies input collection surfaces, third-party data egress sinkholes, and generates tailored ZTDS RFC v1.0 deployment blueprints in under 1.5 seconds.

Sample Perimeters:
MODE 1: ACTIVE SOCKET INTERCEPTOR & VOLATILE RAM AUDITOR

Live Network Socket Interception & Invariant 1 Egress Monitor

Active browser hooks intercept calls to window.fetch and XMLHttpRequest. Test bidirectional sanitization and verify exactly 0.00 bytes cross the perimeter.

Airplane Mode Sim: ONLINE
0 chars
Entities Detected: 0 entities
Intercepted Outbound Network Requests: 0 Requests Dispatched
External WAN Data Egress: ΔEgress = 0.00 Bytes
Memory Boundary Isolation: 100% Client Volatile RAM (Protected)
< 0.18 ms (RAM)
Surrogate tokens will appear here after in-RAM sanitization...
Cryptographic Audit Digest: sha256:7343da5f...
Invariant 1 (Zero-Egress)
Invariant 2 (Bijective)
Invariant 3 (RAM Isolation)
Invariant 4 (No DPA)
Submit Hash to Certification →
Real-Time Network Socket Inspection Console (Active Window Hooks)
Total Packets Monitored: 0
Time Protocol Destination Host Payload Classification WAN Egress Invariant 1 Status
00:00:00.000 INIT localhost (in-memory) Kernel RAM Listener Attached 0.00 Bytes ✓ ZERO EGRESS
MODE 2: IN-BROWSER STATIC CODE LINTER (AST HEURISTICS)

AI Pipeline Code Linter & Conformance Scoring

Analyze your TypeScript, Python, or LangChain pipeline code locally in browser memory against the 4 ZTDS invariants.

Architecture Preset:
18 lines
0.00 B network communication · Local AST Heuristics
Conformance Scorecard
100%
ZTDS Compliant (Green)
Invariant 1: No cleartext PII in uncompiled prompt strings.
Invariant 2: Deterministic surrogate token transformation detected.
Invariant 3: Zero persistence to localStorage, disk, or cookies.
Invariant 4: Subprocessor exclusion confirmed; direct utility execution.
Empirical Reproducibility

The 5-Step Airplane Mode Audit Protocol

Zero-Trust means you do not take our word for it. Any CISO, external auditor, or engineer can independently prove client-side isolation in 30 seconds:

Step 01
Open DevTools

Press F12 or Inspect. Switch to the Network tab and enable Preserve log.

Step 02
Engage Airplane Mode

Disconnect Wi-Fi or set DevTools network throttling to Offline. The machine is now completely isolated.

Step 03
Paste Sensitive Payload

Paste sensitive medical records, patient names, SSNs, or API credentials into the local buffer.

Step 04
Execute In-RAM Engine

Trigger sanitization. Surrogate tokens appear synchronously in volatile memory in < 0.25ms.

Step 05
Verify Zero Egress

Confirm DevTools shows 0 failed socket calls and exactly 0.00 bytes transferred over WAN.

CLI & CI/CD AUDIT WORKBENCH

Continuous Codebase AST Auditing & Pre-Merge Invariant Gating

Verify repositories and block pull requests that leak cleartext secrets before deployment.

bash - ztds-audit
# Run instant in-memory AST audit on local codebase:
npx ztds-audit --dir ./src --verbose

# Terminal Output:
[ZTDS] ZTDS.ai In-Memory Codebase Auditor (RFC v1.0 Conformance)
Files Scanned: 42 files in 18ms
Audit Hash:    sha256:7343da5fed1858d1aabd60684097dc3e192f7...
----------------------------------------------------------------------
[PASS] CONFORMANCE CONFIRMED: 0 INVARIANT VIOLATIONS DETECTED
All scanned files comply with ZTDS Invariant 1 (Zero-Egress) and Invariant 3 (RAM isolation).
Audit Target
Zero Cloud Code Upload

Unlike SaaS static scanners that require read access to private repositories, ztds-audit operates entirely on the local developer node. Zero source files leave the local perimeter.

Deterministic Exit Codes
Strict CI/CD Gating

Returns exit 0 on pure conformance, or exit 1 on unmasked credentials, cleartext PII, or persistent disk storage writes.