Escrowing every agent tool crossing for one period cuts leakage 1,704x, and 65 read-only tools still leak 2,400 bits per call
Provisional Reachability (arXiv 2609.21957, 18 Sep) makes every agent crossing revocable: hold each crossing in escrow for one period, audit held items independently with probability r, and revoke the window on any catch. An adversary crossing k times carrying c bits each expects kc(1-r)^k, maximized at k*=1/ln(1/(1-r)), giving a public-safe bound of about c/(er) per window that simulation matches to 7.7 standard errors. Because escrow bounds a rate rather than a total, the paper adds secret decay and shows an L-bit secret becomes unreachable once decay exceeds g/L, sharp at the predicted threshold across 20,000 windows. The full stack drops a leak from 100,000 to 59 bits while leaving 12% of legitimate work standing, restored to 100% by keying the window per caller, but the honest closing number is that escrow over 65 read-only tools still leaves 2,400 bits per call.
Source
↳ Follow the thread