POL-015 · Vendor endpoints

Model version pinning required

Compiled into the runtime gateway and evaluated inline on every prompt, tool call and completion in scope. Owned by Model Risk.

Triggers / 30d

21

blocks, masks and escalations

Integrations bound

0

enforced at each connection

Severity

medium

owner Model Risk

Added latency

7 ms

p99 within the 60 ms budget

Rule definition

Compiled expression

When

  • provider version differs from approved pin

Then

  • hold traffic
  • notify model owner

Policy as code

apiVersion: truint.ai/v1
kind: RuntimePolicy
metadata:
  id: POL-015
  name: "Model version pinning required"
  owner: "Model Risk"
  scope: "Vendor endpoints"
spec:
  severity: medium
  mode: enforce
  when:
    - "provider version differs from approved pin"
  then:
    - "hold traffic"
    - "notify model owner"

Governance metadata

Policy ID
POL-015
Owner
Model Risk
Scope
Vendor endpoints
State
Enforcing inline
Catalog version
2026.07.3
Last change
2026-07-22 · approved by AI Council

Bound integrations

Where this rule executes

Applies estate-wide rather than to a specific connection.

Recent evaluations

Decisions where this rule fired

No evaluations from this rule in the current buffer.