Archestra Released OpenAPPA Security Engine
The new open-source tool is designed to prevent data exfiltration in agentic AI applications.
Updated on Oct. 4, 2026 in Cybersecurity

Live Poll
Do you trust AI agents to handle sensitive personal or work data securely?
Archestra has launched OpenAPPA, an open-source security engine that monitors agentic AI for potential prompt injection or model hallucination. The tool is currently available in preview as a means to secure data flows.
Why it matters
Stochastic approaches often struggle to track data flow across complex tool calls, leading to either unsafe interactions or overly restrictive agent behavior. OpenAPPA aims to solve this by providing a structured framework for policy enforcement.
OpenAPPA recorded a 0% attack success rate in Bench-Corp and AgentThreatBench testing compared to 31% for Microsoft FIDES. The engine also achieved an 89% task completion rate, significantly outperforming the 41% completion rate of FIDES.
The players
Archestra
Archestra is the developer behind the new open-source security engine OpenAPPA.
UK AI Safety Institute
The UK AI Safety Institute maintains the repository that now includes the AgentThreatBench benchmark.
Microsoft
Microsoft is the technology company that developed the FIDES security framework.
The details
The engine operates outside the agent prompt and execution loop, utilizing lattice algebra to monitor labels for trust levels, audiences, and data sources. Configuration files within the system explicitly define how these authorities interact to prevent unauthorized data exfiltration.
Timeline
October 3, 2026: Archestra released OpenAPPA.
2026: The OWASP Top 10 for Agentic Applications was published.
The Tech Race
The introduction of OpenAPPA reflects a growing industry shift toward formalizing security for autonomous agents, moving away from unreliable stochastic methods. This positions Archestra in direct competition with major tech entities like Microsoft as the industry seeks to replace legacy restrictions with more precise monitoring tools.
Developers and organizations using agentic AI can utilize OpenAPPA to establish clearer trust levels and data source authorities. The tool is designed to improve task completion while maintaining security, potentially allowing for more reliable and functional AI agents in enterprise workflows.
The takeaway
OpenAPPA demonstrates that structural monitoring with lattice algebra can outperform traditional automated policy enforcement. Developers should consider implementing explicit configuration files to better control agent interactions and data exposure.
Further reading
For more information on the evolving standards for securing automated systems, visit our Cybersecurity section.
Source note: This article includes information reported by InfoQ.
Live Poll
Do you trust AI agents to handle sensitive personal or work data securely?







