Skip to content
Klyo Changelog

Hardening against Unicode obfuscation in policy cues

Klyo Context Engine v0.6.3 hardens the cue-matching layer against Unicode obfuscation. Fullwidth and halfwidth variants, Cyrillic and Greek homoglyphs of Latin letters, and zero-width or bidirectional control characters are folded out of the text the engine scans for context cues. An attacker cannot use disguised characters to suppress a sensitive classification or manufacture an escalation cue near real personal data.

The hardening applies only to the cue-scanning surface, never to the content itself, and is paired with the engine’s existing recall guards. Recall on real personal data stays at 100% after the change.

SaaS tenants are already patched. Self-hosted customers should upgrade to v0.6.3.