VAREK, from Sober Agentic Infrastructure (SAI), keeps autonomous AI agents from taking actions they were never authorized to take. Every file access, network connection and program launch is checked against your written policy before it runs, and anything not proven allowed is refused. Enforcement happens at the Linux kernel boundary through seccomp-BPF and seccomp user-notify, so it does not depend on the agent's cooperation. Each decision is recorded in a signed, tamper-evident log that exports as CycloneDX evidence your auditors can verify. Patent-pending.