← All news
ARTICLE
22 September 2026

MSP FAQ: eval-sandbox / CTF-host hygiene when agents touch real orgs

DRAFT FAQ. When a CTF partner enables internet by mistake and agents touch real orgs, EU MSPs should demand eval host isolation, credential planting rules, tenant traffic walls and residual disclosure ownership. Soft Auris posture only. Not a Gemini news restamp.

FAQ: what should an EU MSP demand about eval host isolation after a CTF partner enables internet access by mistake?

When a frontier lab’s CTF evaluation partner mistakenly enables internet access and agents reach real organizations, what should an EU MSP demand about eval host isolation, credential planting rules, customer-tenant traffic walls, and who owns residual disclosure?

Fuel only (second-wave reporting): The Register, 2026-09-21; SecurityWeek — Google confirms Gemini agents accessed three firms. Prefer FAQ framing over restamping the incident as news.

FAQ — Eval host isolation: Demand written proof that CTF/eval hosts cannot reach the public internet or customer production networks unless explicitly approved, time-boxed and logged. Accidental internet enablement must be a hard fail of the eval design.

Credential planting rules: Ask which synthetic credentials may exist on eval hosts, who owns rotation after a spill, and how planted secrets are marked so they never match customer production credentials.

Customer-tenant traffic walls: Require that eval/debug traffic cannot enter customer tenant planes — prompts, artifacts and egress must stay outside approved tenant/region boundaries unless a named legal basis and retention apply.

Who owns residual disclosure? A voluntary or partner-driven incident report does not outsource MSP notice duties. Name the vendor residual owner, escalation path and how reports map into the MSP incident runbook.

# EU MSP eval-sandbox / CTF-host hygiene — FAQ diligence
1. Require written eval-host isolation: no public internet / no customer prod nets unless approved, time-boxed, logged
2. Document credential planting rules; mark synthetic secrets; own rotation after spill
3. Enforce customer-tenant traffic walls for eval/debug prompts and artifacts
4. Name residual disclosure owner + escalation + MSP runbook mapping
5. Treat partner mistakes as design hard-fails, not one-off apologies
6. Soft Auris = product isolation posture only — not a cert; skip Lodestar (403)

Soft Auris posture (product isolation, not a cert): live check at — m2m, tenant_id bound, org_id null, probe ok, 0 violations. Do not invent ACN/C5/SecNumCloud/no-CLOUD-Act claims. Lodestar soft-land skipped (403 org-bind).