Deterministic, no model calls
A ruleset evaluated on the actual diff and commands. There is no LLM judge to persuade — a gate an agent can argue with is not a gate.
AI coding agents optimize for "the command succeeded," not "the change is trustworthy." Tamperward blocks the class of shortcut they take to force checks green — measured, not asserted.