main, 62 unit tests passed at 51.76% statement coverage and 35 integration tests passed. Four long-running HTTP security-service routes are defined behind the authenticated gateway; local Compose uses contract stubs, while production Compose requires independently released product images.
Fail-closed API-key authentication, header isolation, routing, timeout and opaque upstream-error handling.
MCP, LLM red-team, dataset-poisoning, and model-privacy routes. Local Compose validates contracts with stubs.
HF provenance scanning and adversarial evaluation stay outside the synchronous proxy and retain independent release contracts.
Deterministic regex-based ATT&CK v19 seed rules shared by this integration repository.
Requires externally built product images; local health stubs are not published as product images.
No deployed Prometheus/Grafana monitoring or alerting is evidenced by this repository.