Evidence before claims

Case Studies

THOR-SEC separates what is proposed, what is implemented, what is tested, and what is still unproven. Each case study states the problem, the approach, the evidence, the limitations, and the current status.

Current case studies

Research archive
  • Implemented and tested reference implementation

    LLM Agent Control Plane

    A deterministic control boundary for tool-connected LLM agents, with authorization kept outside the model and mapped to automated tests.

    Read case study

  • Formal design; empirical validation pending

    Mission-Invariant Architecture Morphing (MIAM)

    A formal architecture for changing an application's internal service graph so post-access reconnaissance can lose value across security epochs.

    Read case study

  • Implemented prototype; live-provider release gate pending

    Model Identity Verifier

    A CLI that flags model identity drift, provider or route mismatches, downgrade signals, and baseline changes without treating self-description as attestation.

    Read case study

Evidence labels

  • Formal designArchitecture, model, or proposal with defined reasoning or evaluation methods but without empirical efficacy results.
  • Implemented and testedWorking implementation with automated evidence for stated invariants; not automatically a production-readiness claim.
  • PrototypeImplemented system or tool whose validation or release gates are still incomplete.
  • EmpiricalResults backed by measurements under a documented method and population. No current THOR-SEC case study uses this label.