Skip to content

Assessment deployment architecture

AIT occupies one explicit application boundary. The sender is configured to use an AIT listener or wrapper, AIT forwards to the unchanged receiver, and the control plane remains local to the researcher's machine. This is a placement decision, not transparent interception.

A two-host assessment places an explicit AIT data-plane listener between a configured sender and a TLS or mTLS receiver while keeping the control plane on loopback. A two-host assessment places an explicit AIT data-plane listener between a configured sender and a TLS or mTLS receiver while keeping the control plane on loopback. A mobile two-host deployment view separating sender configuration, the AIT data plane, the loopback control plane, TLS upstream delivery, receiver state, and evidence. A mobile two-host deployment view separating sender configuration, the AIT data plane, the loopback control plane, TLS upstream delivery, receiver state, and evidence.

The researcher controls the route into AIT and the upstream configuration. The sender and receiver remain the systems selected for the assessment. A transcript establishes delivery; receiver state or another authorized observation source establishes what followed.

Placement by transport

Communication Explicit placement Boundary controlled
A2A JSON-RPC or REST Replace the receiver URL with the AIT HTTP or HTTPS listener Complete request and response envelopes
A2A gRPC Replace the service endpoint with the A2A-specific bridge Supported A2A service messages, not arbitrary gRPC
MCP Streamable HTTP Replace the MCP origin with the AIT listener Initialization, requests, responses, notifications, and SSE events
MCP stdio Replace the server command with the wrapper AIT prints Framed stdin and stdout messages without a shell
SSE or WebSocket Replace the stream origin with the explicit relay Complete events or messages, including release order and replay

If the sender cannot be configured to use the listener or wrapper, AIT cannot occupy that hop. It does not change DNS, poison name resolution, install a trust root, or redirect network traffic.

Trust and credential locations

Location Material present Research implication
Sender Its normal target configuration and any credential it normally sends Repointing the sender is the authorized placement step
AIT data plane Raw message envelopes, including credentials carried by the selected exchange Raw captures are sensitive; the operator can see what the protocol carries
AIT control plane Connection references, decisions, and local authorization token It stays on loopback even when the data plane binds a routable address
Receiver Its own TLS identity, policy, storage, and action credentials AIT does not need receiver code execution or model access
Evidence source The minimum authorized state needed to judge the effect It must not be inferred from the transcript or receiver narration alone

Credential values belong in environment-backed or connection references where the platform accepts them. A raw transcript necessarily retains values that cross the selected boundary. Export redacted evidence by default and keep raw records on an encrypted operator volume.

TLS boundaries

There are two independent TLS questions:

  1. What does the sender trust? If it requires HTTPS, supply a listener certificate whose SAN names the address the sender dials.
  2. What does AIT trust upstream? Use system roots, add a private CA, or configure mTLS client material on the connection.

AIT does not mint a trusted interception certificate. Supplying insecure_skip_verify changes the security property of the assessment path and must be recorded as a deliberate exception, not treated as equivalent to a private CA.

Evidence maturity by path

Implementation support and external validity are different claims.

Path Repository-backed evidence Limit
A2A JSON-RPC and REST Complete-frame adapter tests and process-backed controlled labs A lab result does not describe an external coordinator
A2A gRPC Protocol-specific bridge and transport tests Not a general gRPC proxy
MCP Streamable HTTP Adapter and controlled-lab coverage Target behavior still needs a target-owned observation
MCP stdio Packaged wrapper acceptance against a third-party server One server does not establish ecosystem-wide compatibility
Remote listener plus TLS Automated placement rehearsal and a two-host field procedure Network policy and certificate trust remain environment-specific
Framework-mediated traffic A framework can be placed only where it emits a supported boundary Installing or importing a framework is not execution evidence

When a row lacks a named test or retained field record, treat the path as unverified for the current checkout.

Field procedure

  1. Record the exact sender, receiver, protocol binding, locator, and authorized effect before starting a listener.
  2. Name what must never happen, such as a real payment, message, deletion, or cross-tenant access.
  3. Prepare the connection without contact and inspect the routing change.
  4. Confirm control-plane loopback binding and the exact data-plane interface.
  5. Validate certificate names, upstream trust, and credential references.
  6. Start with interception off and send one low-risk operation unchanged.
  7. Confirm that the inert path preserves framing, streaming, timing, and target behavior.
  8. Reset target state and take the oracle baseline.
  9. Run one bounded attack arm and one close control against the same target state and topology.
  10. Read sender bytes, delivered bytes, receiver state, and effect evidence as separate records.
  11. Export redacted evidence, resolve pending messages, stop every owned process, and verify cleanup.

Cancellation and recovery

A paused message holds a real connection. Set a pending timeout and an explicit timeout action for any unattended session. Stop cooperatively first; AIT then terminates its owned process group. After interruption, do not resume a removed compound campaign. Start a new bounded run after verifying that listeners, callbacks, browser contexts, trace receivers, and target namespaces are clean.

Offline work

Because this is a source-access research platform, prepare the reviewed checkout and its locked dependencies before entering a restricted environment. Confirm the packaged Seam binary, run ait doctor, and exercise the exact transport in the controlled lab. Do not rely on an unverified wheel or release archive as a substitute for the reviewed source state.

Continue with Taking it to a real target for connection details and Two-host field rehearsal for the real network boundary.