QWED v4.0.0 Sentinel Edition is now live β Agentic Security Guards, Process Determinism, and 147 commits of hardening. See whatβs new β
What is QWED?
QWED (Query With Evidence & Determinism) is a model-agnostic verification protocol for Large Language Models.βTrust, but Verify.β β QWED treats LLMs as untrusted translators and uses symbolic engines as trusted verifiers. Your LLM, Your Choice, Our Verification.
Quick Start
Why QWED?
LLMs hallucinate math
QWED uses SymPy for symbolic verification β algebraic proof, not pattern matching.
LLMs break logic
Z3 SAT solver provides formal satisfiability checks with model generation.
LLMs generate unsafe code
AST analysis + pattern detection catches vulnerabilities before execution.
LLMs produce SQL injection
Query parsing + schema validation catches injections and malformed queries.
11 Verification Engines
Math
Symbolic algebra with SymPy
Logic
SAT/SMT solving with Z3
Code
AST security analysis
SQL
Query validation & injection detection
Fact
NLI-based fact checking
Stats
Statistical claim verification
Reasoning
Chain-of-Thought verification
Image
Visual content verification
Graph
Knowledge graph fact checking
Schema
JSON/API schema validation
Taint
Data flow taint analysis
Model Agnostic = Your Choice
Send queries through QWED
QWED routes LLM responses through the appropriate symbolic engine for verification.
Ecosystem & SDKs
Python SDK
pip install qwed β Full-featured SDK with CLI.TypeScript SDK
npm install @qwed-ai/sdk β Browser and Node.js support.Go SDK
Lightweight Go module for backend services.
Rust SDK
cargo add qwed β Zero-cost abstractions.π Whatβs New in v4.0.0: Sentinel Edition
The v4.0.0 Sentinel Release introduces Agentic Security Guards, Process Determinism, and critical security hardening. 147 commits β the largest update in QWED history.Agentic Security Guards (Phase 17)
Agentic Security Guards (Phase 17)
- RAGGuard β Detects prompt injection and data poisoning in RAG pipelines.
- ExfiltrationGuard β Prevents data exfiltration through agent tool calls.
- MCP Poison Guard β Detects poisoned MCP tool definitions.
New Standalone Guards
New Standalone Guards
- SovereigntyGuard β Data residency and local routing enforcement.
- ToxicFlowGuard β Stateful toxic tool-chaining detection.
- SelfInitiatedCoTGuard β Reasoning integrity verification.
Process Determinism
Process Determinism
- ProcessVerifier β IRAC/milestone-based verification with decimal scoring, budget-aware timeouts, and structured compliance reporting.
Security Hardening
Security Hardening
- Replaced all
eval()with AST-compiled execution. - Patched sandbox escape, SymPy injection, and protocol bypass vulnerabilities.
- Resolved CVE-2026-24049 (Critical), 19 Snyk findings, and CodeQL alerts.
Full Changelog
See the complete release history including v3.0.1 Ironclad and v2.4.1 Reasoning Engine.