QWED v4.0.0 Sentinel Edition is now live β Agentic Security Guards, Process Determinism, and 147 commits of hardening. See whatβs new β
What is QWED?
QWED (Query With Evidence & Determinism) is a model-agnostic trust boundary for AI systems.βDonβt fix the liar. Verify the lie.β β QWED verifies outputs, processes, and tool interactions before they enter production. It doesnβt reduce hallucinations β it makes them irrelevant.
Quick Start
Why QWED?
LLMs hallucinate math
QWED uses SymPy for symbolic verification β algebraic proof, not pattern matching.
LLMs break logic
Z3 SAT solver provides formal satisfiability checks with model generation.
LLMs generate unsafe code
AST analysis + pattern detection catches vulnerabilities before execution.
LLMs produce SQL injection
Query parsing + schema validation catches injections and malformed queries.
11 Verification Engines
Math
Symbolic algebra with SymPy
Logic
SAT/SMT solving with Z3
Code
AST security analysis
SQL
Query validation & injection detection
Fact
NLI-based fact checking
Stats
Statistical claim verification
Reasoning
Chain-of-Thought verification
Image
Visual content verification
Graph
Knowledge graph fact checking
Schema
JSON/API schema validation
Taint
Data flow taint analysis
Model Agnostic = Your Choice
Send queries through QWED
QWED routes LLM responses through the appropriate symbolic engine for verification.
Ecosystem & SDKs
Python SDK
pip install qwed β Full-featured SDK with CLI.TypeScript SDK
npm install @qwed-ai/sdk β Browser and Node.js support.Go SDK
Lightweight Go module for backend services.
Rust SDK
cargo add qwed β Zero-cost abstractions.π Whatβs New in v4.0.0: Sentinel Edition
The v4.0.0 Sentinel Release introduces Agentic Security Guards, Process Determinism, and critical security hardening. 147 commits β the largest update in QWED history.Agentic Security Guards (Phase 17)
Agentic Security Guards (Phase 17)
- RAGGuard β Detects prompt injection and data poisoning in RAG pipelines.
- ExfiltrationGuard β Prevents data exfiltration through agent tool calls.
- MCP Poison Guard β Detects poisoned MCP tool definitions.
New Standalone Guards
New Standalone Guards
- SovereigntyGuard β Data residency and local routing enforcement.
- ToxicFlowGuard β Stateful toxic tool-chaining detection.
- SelfInitiatedCoTGuard β Reasoning integrity verification.
Process Determinism
Process Determinism
- ProcessVerifier β IRAC/milestone-based verification with decimal scoring, budget-aware timeouts, and structured compliance reporting.
Security Hardening
Security Hardening
- Replaced all
eval()with AST-compiled execution. - Patched sandbox escape, SymPy injection, and protocol bypass vulnerabilities.
- Resolved CVE-2026-24049 (Critical), 19 Snyk findings, and CodeQL alerts.
Full Changelog
See the complete release history including v3.0.1 Ironclad and v2.4.1 Reasoning Engine.