> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/8.-security-and-enforcement/8.-security-and-enforcement.md).

# 8. Security & Enforcement

LPP security is built around a specific objective:

> **Prevent an AI-triggered action from producing governed external effect without valid authority, valid scope, valid execution authorization, and reconstructable governance state.**

This is different from attempting to make the underlying AI model incapable of producing unsafe or unauthorized proposals.

The LPP security model assumes that an adversarial or malfunctioning agent may still:

* generate unauthorized actions,
* attempt prompt injection,
* impersonate authority,
* expand scope,
* reuse authorization,
* exploit revocation latency,
* downgrade policy,
* invoke tools directly,
* or attempt to influence the Control Plane.

The enforcement architecture therefore places critical controls outside the model's own reasoning process.

The canonical security path is:

```
Principal
        ↓
Authority
        ↓
Scope
        ↓
Intent / Consequence
        ↓
LPP Admission
        ↓
Execution Permit
        ↓
Non-Bypassable Execution Boundary
        ↓
Execution
        ↓
Admission Artifact
```

The core security principles are:

```
No valid authority
→ No legitimate execution

Out-of-scope action
→ No valid execution path

Revoked authority
→ No continued legitimate reliance

Invalid or replayed Permit
→ No execution

Undefined mandatory governance state
→ Fail closed

Execution Plane
→ Cannot self-authorize
```

Security depends on maintaining these invariants structurally rather than trusting the agent to obey them voluntarily.

***

###
