drop vector store + provenance log · detect poisoning insertions · runs locally
vector store + provenance · local only
heuristic screener · vendor schema varies · not definitive proof