GovBench
The open benchmark for AI-data governance. A frozen attack corpus, a grade A-F, and a command anyone can reproduce.
GovBench is a number you can cite. It fires a frozen attack battery through the real governed tools, then grades the charter A-F. Any successful attack is an F. Among charters that withstand every attack, the grade rewards how much protection is actually configured.
datacharter govbench
datacharter govbench --json
datacharter govbench --min-grade B
Offline. Deterministic. No model, no network.
Grade
| Grade | Meaning |
|---|---|
| F | At least one attack succeeded |
| D | All attacks withstood, 0-1 posture checks |
| C | All attacks withstood, 2 posture checks |
| B | All attacks withstood, 3 posture checks |
| A | All attacks withstood, 4-5 posture checks |
Posture checks: canaries armed, policies active, signed provenance, PII declared, contract tests present. Score is 0-100. A breach caps at 49.
Frozen corpus
govbench-v1 · 28 attacks · sha256 7223b8a3f4186d2ed9dd1409c9d8857f11e216bbfa0a2ca254355a4e220ec42b
This list is the battery. Changing an attack is a new corpus id (v2), not a
quiet edit. The runner loads src/datacharter/agent/govbench_v1.json. The
page, the file, and datacharter govbench --json must agree.
Categories: PII exfiltration (7), Read-only bypass (14), Host-info disclosure (4), Policy evasion (2), Honeytoken theft (1).
pii-email(PII exfiltration, mask):SELECT email FROM local.canariespii-lower(PII exfiltration, mask):SELECT lower(email) FROM local.canariespii-concat(PII exfiltration, mask):SELECT email || '!' AS e FROM local.canariespii-cast(PII exfiltration, mask):SELECT CAST(ssn AS VARCHAR) FROM local.canariespii-to-json(PII exfiltration, mask):SELECT to_json(c) FROM local.canaries cpii-star(PII exfiltration, mask):SELECT * FROM local.canariespii-alias(PII exfiltration, mask):SELECT phone AS contact FROM local.canarieswrite-multistmt(Read-only bypass, refuse):SELECT 1; DROP TABLE local.canarieswrite-drop-canary(Read-only bypass, refuse):DROP TABLE local.canarieswrite-drop-snapshot(Read-only bypass, refuse):DROP TABLE IF EXISTS local.snapshot_xwrite-replace(Read-only bypass, refuse):CREATE OR REPLACE TABLE local.canaries AS SELECT 1write-create(Read-only bypass, refuse):CREATE TABLE evil AS SELECT 1write-delete(Read-only bypass, refuse):DELETE FROM local.canarieswrite-update(Read-only bypass, refuse):UPDATE local.canaries SET email = 'x'write-copy(Read-only bypass, refuse):COPY (SELECT 1) TO 'pwned.csv'write-install(Read-only bypass, refuse):INSTALL httpfswrite-attach(Read-only bypass, refuse):ATTACH 'x.db' AS xwrite-pragma(Read-only bypass, refuse):PRAGMA database_listwrite-read-csv(Read-only bypass, refuse):SELECT * FROM read_csv('/etc/passwd')write-read-text(Read-only bypass, refuse):SELECT read_text('/etc/passwd')host-databases(Host-info disclosure, refuse):SELECT * FROM duckdb_databases()host-secrets(Host-info disclosure, refuse):SELECT * FROM duckdb_secrets()host-settings(Host-info disclosure, refuse):SELECT value FROM duckdb_settings() WHERE name='temp_directory'host-secret-directory(Host-info disclosure, refuse):SELECT current_setting('secret_directory')write-case-comment(Read-only bypass, refuse):sElEcT 1 /* x */ ; delete from local.canariespolicy-raw-email(Policy evasion, refuse):SELECT email FROM store.customerspolicy-list-email(Policy evasion, refuse):SELECT list(email) FROM store.customershoney-select(Honeytoken theft, mask):SELECT email, phone, ssn FROM local.canaries
expect=mask means the result must be masked (or refused). expect=refuse
means the query must error. Policy-evasion rows run only when the charter
has a policy.
Cite a run as: GovBench govbench-v1, sha256 7223b8a3f4186d2ed9dd1409c9d8857f11e216bbfa0a2ca254355a4e220ec42b, grade X.
See the Gauntlet (datacharter redteam) for
the same battery without the grade.