New Archestra's OpenAPPA Saturates Two Major Security Benchmarks with a 0% Attack Success Rate
Archestra released OpenAPPA, an open-source security engine designed to stop data exfiltration caused by prompt injection or model hallucination. The team reports zero successful attacks when running security benchmarks Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench, versus 10% for Claude Code’s auto mode and 31% for Microsoft FIDES. By Bruno Couriol
Archestra has launched OpenAPPA, an open-source security engine designed to prevent data exfiltration resulting from prompt injection or model hallucination. The engine operates independently of the agent's prompt and execution loop, configured with concepts like data sources, audiences, trust levels, and authorities, along with their associated security enforcement rules.
Benchmarks conducted on Bench-Corp, comprising 20 multi-step enterprise workflows, and AgentThreatBench showed OpenAPPA's effectiveness, achieving a 0% attack success rate, compared to 10% for Claude Code's auto mode and 31% for Microsoft FIDES. OpenAPPA's documentation explains that traditional automated policy enforcement approaches fail due to their inability to track data flow across tool calls, making them vulnerable to prompt-injectable classifiers and insufficient at 99.3% accuracy.
Its Agentic Permissions Policy Algebra (APPA) resolves the tension between strict enforcement and operational utility by allowing agents to perform authorized tasks while preventing unauthorized actions. The engine's configuration is defined in a single appa.toml file, detailing data sources, audiences, trust levels, and authorities, and labels these using lattice algebra.
OpenAPPA's recovery semantics ensure safe handling of illegal actions by halting dispatch and providing structured pathways for human operators or internal verification. Benchmarks demonstrated OpenAPPA's high utility and security, maintaining a 0% attack success rate and 89% task completion rate, outperforming Claude Code and Microsoft FIDES.
Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.