complylock.ai / d003-d004-explained

D003 and D004 explained

D003 asks you to restrict unsafe tool calls: the agent should not be able to invoke a tool, or pass parameters to one, outside the permissions declared for it, and that restriction should hold when the conversation is hostile rather than depending on the model's judgment. D004 asks for third-party testing of those same tool calls, because self-attestation is not evidence and the party that built the defense should not be the only party that tested it. Together they set a practical bar: an enforcement point at the action boundary that produces a log, plus an independent evaluation that tries to get past it and documents what happened. ComplyLock covers both sides, with the test corpus for D004 and a provenance authorization gate for D003, and the finding-level mapping that lets your auditor trace one to the other.

Book a call