CHANGE-AWARE SECURITY REGRESSION + RELEASE GATE

Every agent change gets the security assurance it requires.

DiffGate uses reviewed Agent Security Context plus PR impact analysis to determine which security guarantees a release can affect, then creates or selects the required assurance before release.

Gemini reasons. Deterministic enforcement decides.

CONTROL FLOW

  1. PR
  2. Security Impact
  3. Create / Select Assurance
  4. Controlled Execution
  5. Deterministic Evidence
  6. ALLOW / BLOCK

NEW / CHANGED SECURITY SURFACE

Fresh assurance + relevant regression

KNOWN PROTECTED CHANGE

Relevant stored regression

NO PROTECTED AGENT IMPACT

No deep assurance