Antigense Daisy is a verifiable agentic cyberdefense prototype for AppSec teams confronting a dangerous failure mode: a corrupted AI-worker result triggers a fail-open authorization decision. In a controlled software fixture, we inject a byte fault, detect the integrity mismatch, reproduce the unsafe fallback, identify it with Semgrep, and test a pinned fail-closed correction while preserving authorized work. AI-generated remediation advice cannot apply a patch without review.
Each recorded step is an addressable Fractal Custody Object (FCO), linked by typed relationships in a Fractal Custody Graph (FCG). Ordered Merkle/MMR checkpoints preserve state transitions; browser and Python verifiers independently recompute the recorded commitments. A separate executed local run contains 12 MMR leaves, including an actual browser-bound review action and its predecessor edge; the public proof page permits recomputation.
Sponsor evidence: Semgrep executed before/after local scans and identified an additional unsafe exec() call in our agent code, later removed. ClickHouse Cloud ingested and exactly read back 11 incident checkpoints. A separate Akash GPU deployment returned model advice via HTTP 200 and a successful close-request response. Earlier Akash HTTP 401 failure is retained; Pi Security execution is NOT_TESTED. The narrated video replays historical evidence, not new cloud API calls. Hashes prove integrity of declared bytes, not security, attribution or causality.