Resources
Claix Trust
Verify every file before it becomes context. Claix Trust blocks malicious content and unsafe instructions before they reach document processing, RAG memory, or AI agents.
It runs on every format Claix accepts — PDF, spreadsheets, documents, images, audio, and text — and it runs before any parser, model, or knowledge space sees the file. A file that fails a critical check is not opened, not converted, and not remembered.
Protected endpoints
Why it matters
A document is an input to an agent, not just a file
Backends, RAG pipelines, and agents treat an upload as trusted context. A PDF, a spreadsheet, an image, or an HTML snippet can carry more than the fields you asked for: scripts, macros, remote links, hidden text, and instructions written for the model rather than for a person.
Once that content is parsed, transcribed, or stored in a knowledge space, it is hard to take back. It can steer an answer, poison later retrieval, or ride into the next agent call. The damage happens after ingestion, so the check has to happen before it.
Claix Trust is that check. It decides whether a file is safe to open, convert, and remember. It does not replace Source Tracing. Trust protects the path in. Source Tracing makes the result auditable after the file is in.
Every upload
Checks that apply to every file, before the format-specific review
These run first, with no exception. If something critical fails here, Claix stops. Nothing after that point reads the file.
The file is what it claims to be
The name and the declared type have to match the file itself. A renamed executable, a picture labeled as a PDF, or a document that is actually another format is rejected instead of being opened.
- Content that does not match the extension
- Executables disguised as documents
- Empty files
- Files larger than the endpoint allows
- Types Claix does not support, rejected rather than opened anyway
Names that hide what the file is
The file name is part of the attack. Claix Trust rejects names that disguise the extension, escape a folder, or impersonate a system device.
- Characters that display a different extension than the one stored
- A second extension that hides an executable
- Path fragments inside the name
- Reserved device names
- Null bytes embedded in the name
Archives built to exhaust or to smuggle
Spreadsheets and Word files are containers. Claix Trust refuses the ones built to blow up a server, to hide another archive inside, or to climb out of their own folder.
- Compression bombs
- Nested archives inside the container
- Far too many entries
- Uncompressed size that dwarfs the upload
- Paths that climb out of the archive
- Archives with no readable directory, no entries, or an unsupported archive variant
Instructions meant for the model
After a safe file becomes text, Claix Trust reads that text for content a person would not see and a model might obey. A quoted phrase in a normal document is not enough, on its own, to reject it. Hidden channels and a clear attempt to override the system are.
- Invisible characters and characters that take no space
- Characters that reverse how the text is displayed
- Hidden instructions and imperative overrides
- Forged source-tracing markers that pretend a value was cited
Every format
What Claix Trust prevents in each format
The generic checks always run first. Then the review that belongs to that format. No supported format is left without its own layer.
PDF
A PDF can run code, hide text, and carry other files. Claix Trust stops those before the document is read or sent on for extraction.
- Scripts embedded in the document
- Actions that run when the file opens, or on later events
- Other files embedded inside the PDF
- Actions that launch an external program
- Links that run script, open a local file, or carry an HTML payload
- Forms that submit data to a remote target
- Rich media, movies, and sound used as a payload
- Dynamic forms and optional content layers
- Encrypted documents that cannot be inspected
- Text painted so a person cannot see it, including text the same color as the page
- Content concealed inside compressed parts of the file
- Names disguised so a casual read misses them
- Missing or broken structure: no real header, no end of file, a bad cross-reference, unbalanced objects, or no pages
- A page count that does not make sense for the size of the file
Word, RTF, Excel, and CSV
Documents and spreadsheets share one review, because macros, embedded objects, and remote links show up in both. Legacy binary Word and Excel files are not accepted as modern documents.
- Macros, including files marked as macro-enabled
- Embedded objects and packaged payloads
- Relationships that attach a remote template, a sub-document, another workbook, or an embedded package
- Links and targets that point at the local machine
- Spreadsheet formulas that call external services, import remote data, or launch a command
- Cells that start like a formula so another spreadsheet will execute them later
- External data connections and external workbook links
- Named ranges that reach outside the workbook
- Hidden sheets, and hidden rows that still contain values
- Fields that pull remote text or images, or that start a data exchange with another program
- Attached templates loaded from outside the file
- Markup inside the package that tries to pull external data into the document
- RTF that is structurally invalid, excessively nested, or that carries binary objects, a datastore, or an external field
- A spreadsheet packaged as a document, or the reverse
- Corrupt packages, unsafe paths inside the package, and CSV that is actually binary or has no line structure
Images
JPEG, PNG, WebP, HEIC, and HEIF. The pixels are not the only thing a model will read. Metadata can carry instructions that never appear in the image.
- A format that does not match the extension
- A declared type that disagrees with the file
- Files that do not end where the image ends
- A declared size that does not match the container
- Data appended after the image
- Dimensions that do not match the file size, including images built to exhaust memory when decoded
- Metadata that is anomalously large
- A payload hidden beside the image data
- Instructions stored in metadata, which can reach a prompt without appearing in any pixel
Audio
MP3, WAV, M4A, and OGG. Claix Trust checks the recording before it is transcribed, and it checks the tags, because a comment field can steer a model without ever being spoken.
- A container that does not match the extension
- A declared type that disagrees with the file
- A declared size that overflows the file
- Data after the audio ends
- Malformed containers, missing streams, and unexpected gaps
- Padding large enough to hide something else
- An empty stream, or a duration that does not match the size
- Files far longer than a normal upload
- A payload hidden in the file, or instructions stored in tags such as title, artist, or comments
Text, HTML, XML, and JSON
With no binary layer to reject first, the content itself carries more of the risk. Hidden text is weighed more heavily, because hiding it is already a signal.
- Encodings Claix does not accept, invalid text, and binary content labeled as text
- Text with no line structure, or text over the size the endpoint allows
- Markup that does not belong in a plain-text upload
- Scripts, event handlers, iframes, embedded objects, and applets
- Pages that refresh to another address, rewrite their base URL, or load external resources
- Links that run script or carry an active payload
- Stylesheets whose only job is to hide content
- Text hidden from a reader — off-screen, transparent, zero-size, or clipped — that is still present for a model
- XML that declares a document type, entities, or an external reference
- Includes and transforms that pull in outside markup
- Processing instructions, excessive nesting, and elements that are never closed
- JSON that is not valid JSON
- Keys that try to alter how the object behaves, including reserved names
- JSON nested or repeated until it would exhaust a parser
What it prevents
The failures Claix Trust is there to stop
Each check above exists because that failure has a cost after the file is inside the system. Together they cover the path from the upload to the moment a model, a knowledge space, or an agent would otherwise treat the file as ordinary context.
- Prompt injection that arrives inside a customer file instead of in the chat.
- Malware and executables uploaded under a document name.
- Macros and embedded objects reaching a parser.
- Formulas that leave Claix and execute when someone opens the spreadsheet elsewhere.
- Decompression bombs and pathological files used to exhaust the service.
- Hidden text becoming RAG memory and coming back in a later answer.
- Image metadata or audio tags steering an extraction without appearing in the pixels or the recording.
- A poisoned document stored in a knowledge space and retrieved by an agent days later.
- Forged citations that look like Source Tracing.
- A file Claix cannot inspect in time. It is rejected. It is not processed while the check is still unfinished.
Where it sits
Before processing, before memory, before the agent
Claix Trust is not a separate product you call. It is the first step of ingestion, on extraction, on Markdown conversion, and on agent calls.
| Without the check | With Claix Trust |
|---|---|
| The parser, the model, or the agent is the first thing to touch the file. | The file is verified before it is parsed, converted, or sent on. |
| A bad upload can be written into a knowledge space. | A blocked file is not stored as memory. |
| An agent call spends the extraction and then builds a prompt from the raw file. | The agent call is checked first, before that work starts. |
| A typed JSON answer can still be grounded in a hostile document. | Trust decides whether the file may enter. Source Tracing then decides whether each field is grounded. |
Questions
- Does Claix Trust change a successful response?
- No. A file that passes is processed as before, and the response keeps the same shape. A file that fails a critical check is rejected with an error and is not processed.
- Which calls does it cover?
- Every document endpoint: PDF, Excel and CSV, Word, RTF and text documents, images, audio, and text, HTML, XML, and JSON — both the extraction and Markdown routes, and the agent routes in front of them.
- Does it replace Source Tracing?
- No. Claix Trust runs before the file is ingested. Source Tracing runs on the extracted fields, attaching evidence or marking a field for human review when the document does not support the answer.
- Will a legitimate document that quotes an attack be rejected?
- A single awkward sentence is not enough to reject a normal document. Hidden channels, scripts, macros, and a clear attempt to override the system still stop the file.
- Do I call Claix Trust myself?
- No. It is part of ingestion. You keep calling the same endpoints.
- What happens to a file that looks suspicious but is not conclusively dangerous?
- Critical findings stop the file. Suspicious findings are recorded in the audit trail and do not, by themselves, reject a legitimate document.
The file is checked before anything else can trust it.
Extraction, Markdown, knowledge spaces, and agents all start from the same upload. Claix Trust is the gate in front of that path: secure ingestion first, then source-grounded extraction, schema-validated output, and human review when an answer cannot be verified.