Archestra Released OpenAPPA Security Engine

The new open-source tool is designed to prevent data exfiltration in agentic AI applications.

Updated on Oct. 4, 2026 in Cybersecurity

Isometric editorial illustration showing a series of interlocking crystalline prisms, symbolizing structured security for data flows.
Archestra has launched OpenAPPA, an open-source security engine designed to monitor agentic AI applications and prevent unauthorized data exfiltration. AI Illustration. Upload story photo >

Live Poll

Do you trust AI agents to handle sensitive personal or work data securely?

Archestra has launched OpenAPPA, an open-source security engine that monitors agentic AI for potential prompt injection or model hallucination. The tool is currently available in preview as a means to secure data flows.

Why it matters

Stochastic approaches often struggle to track data flow across complex tool calls, leading to either unsafe interactions or overly restrictive agent behavior. OpenAPPA aims to solve this by providing a structured framework for policy enforcement.

OpenAPPA recorded a 0% attack success rate in Bench-Corp and AgentThreatBench testing compared to 31% for Microsoft FIDES. The engine also achieved an 89% task completion rate, significantly outperforming the 41% completion rate of FIDES.

The players

Archestra

Archestra is the developer behind the new open-source security engine OpenAPPA.

UK AI Safety Institute

The UK AI Safety Institute maintains the repository that now includes the AgentThreatBench benchmark.

Microsoft

Microsoft is the technology company that developed the FIDES security framework.

The details

The engine operates outside the agent prompt and execution loop, utilizing lattice algebra to monitor labels for trust levels, audiences, and data sources. Configuration files within the system explicitly define how these authorities interact to prevent unauthorized data exfiltration.

Timeline

  1. October 3, 2026: Archestra released OpenAPPA.

  2. 2026: The OWASP Top 10 for Agentic Applications was published.

The Tech Race

The introduction of OpenAPPA reflects a growing industry shift toward formalizing security for autonomous agents, moving away from unreliable stochastic methods. This positions Archestra in direct competition with major tech entities like Microsoft as the industry seeks to replace legacy restrictions with more precise monitoring tools.

Developers and organizations using agentic AI can utilize OpenAPPA to establish clearer trust levels and data source authorities. The tool is designed to improve task completion while maintaining security, potentially allowing for more reliable and functional AI agents in enterprise workflows.

The takeaway

OpenAPPA demonstrates that structural monitoring with lattice algebra can outperform traditional automated policy enforcement. Developers should consider implementing explicit configuration files to better control agent interactions and data exposure.

Further reading

For more information on the evolving standards for securing automated systems, visit our Cybersecurity section.

Source note: This article includes information reported by InfoQ.

Live Poll

Do you trust AI agents to handle sensitive personal or work data securely?