# kaal:claim:7314479-034

**Claim.** The Gatekeeper documentation at commit 2d920ce specifies four filtering layers, but the implementation contains only the domain allowlist and audit logging; content inspection and personal-information filtering are absent from the code.

**Type.** empirical  **Support.** evidenced

**Holds when.**

- mosaic-companion public repository at commit 2d920ce, retrieved August 18, 2026

**Source quote.**

> The Gatekeeper documentation specifies four filtering layers: domain allowlist, content and MIME type inspection, a personal-information baseline using regular expressions and named-entity recognition, and audit logging. The implementation contains the first and the fourth.

**From.** Wulf A. Kaal, *Institutional Requirements for Sovereign Local Agent Runtimes* (2026), VII. Findings, Finding 6, page 16

**Cite as.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Verify.** sha256 of source PDF `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6` at https://raw.githubusercontent.com/wulfkaal/Academic-Papers/main/papers/pdf/Kaal%20-%202026%20-%20Institutional%20Requirements%20for%20Sovereign%20Local%20Agent%20Runtimes.pdf

**Topics.** disclosure, open-source-and-code, ai-and-agents

**Canonical form.** This markdown file is the canonical hashed representation of the claim. Its sha256 is the content hash used for attestation.
