POL-015 · Vendor endpoints
Model version pinning required
Compiled into the runtime gateway and evaluated inline on every prompt, tool call and completion in scope. Owned by Model Risk.
Triggers / 30d
21
blocks, masks and escalations
Integrations bound
0
enforced at each connection
Severity
medium
owner Model Risk
Added latency
7 ms
p99 within the 60 ms budget
Rule definition
Compiled expression
When
- provider version differs from approved pin
Then
- hold traffic
- notify model owner
Policy as code
apiVersion: truint.ai/v1
kind: RuntimePolicy
metadata:
id: POL-015
name: "Model version pinning required"
owner: "Model Risk"
scope: "Vendor endpoints"
spec:
severity: medium
mode: enforce
when:
- "provider version differs from approved pin"
then:
- "hold traffic"
- "notify model owner"Governance metadata
- Policy ID
- POL-015
- Owner
- Model Risk
- Scope
- Vendor endpoints
- State
- Enforcing inline
- Catalog version
- 2026.07.3
- Last change
- 2026-07-22 · approved by AI Council
Bound integrations
Where this rule executes
Applies estate-wide rather than to a specific connection.
Recent evaluations
Decisions where this rule fired
No evaluations from this rule in the current buffer.