Skip to main content
Runlayer security models are continuously retrained against emerging threat patterns. Because a model update can shift scan scores — and therefore the composition of blocked versus allowed traffic — every production model version is recorded here so you can correlate changes in your security dashboard with model rollouts. Model updates are grouped by the scanning capability they affect:
  • Tool scanning — Tool List Guard, Tool Call Guard, and IO Guard, scoring MCP tool lists and tool calls.
  • Topic & skill scanning — topic classification, tool-removal detection, and SkillGuard skill scanning.
A new row is added whenever a new model version is rolled out. If you notice a shift in block rates or scan scores, check this page first to see whether a model update coincides with the change. A row only affects you if the corresponding capability is enabled in your deployment — for example, SkillGuard model updates have no effect unless skill scanning is turned on for your organization. Model rollouts are managed entirely by Runlayer: no upgrade, version bump, or other action is required on your side.

Model versions

Version tags are timestamped (vYYYYMMDDhhmm) and identify the exact model bundle serving your deployment.

Monitoring ToolGuard availability

ToolGuard reachability is monitored continuously and reported on your Runlayer status page alongside frontend and API health. Contact your Runlayer representative if you don’t have access to your status page.

ToolGuard Models

What each ToolGuard model does and how to configure it

Changelog

Platform release notes