This wins on execution and honesty, not on novel cryptography. It is not “unbreakable” — nobody’s is, and we do not claim it. The architecture is not new: dummy keys plus an injecting proxy already ship as open-source and commercial products.
It reduces accidental key exposure for cooperative clients. It does not make a hijacked agent safe, and the current same-user launcher cannot prevent a malicious child from reading Airlock data or its admin token. Policy and approval do not repair that missing OS boundary.
Airlock configures cooperative HTTP(S) clients to use its proxy; it is not an operating-system network sandbox. A child process that deliberately opens a direct socket can bypass that proxy unless you add an OS-enforced egress boundary.