Cryptographic agentic registration
Cryptographic agent identity with a self-enrollment SDK; every agent action is written to an append-only, hash-chained (tamper-evident) audit log.
Virtual-key LLM gateway
OpenAI/Anthropic-compatible proxy with per-key budgets, rate limits, and model allow-lists — the OWASP LLM10 control. Real provider keys stay in your vault.
Inline ML firewall — 13 detectors
DistilBERT-based inline inspection of prompts and responses across 13 detectors and 400+ threat signatures, on an allow / flag / redact / block matrix.
Prompt-injection detection
Fused heuristic + ML detection that defeats evasion and obfuscation on multi-layer and multi-turn injection attempts.
PII detection & redaction
Fused ML + rules pipeline that redacts SSNs, emails, secrets, and financial/health data inline, before anything leaves your environment.
MCP security
Sanction which MCP servers and tools an agent may reach; inspect every tool call — arguments and results — with full session replay.
Tool-call validation
Argument-level inspection and blocking of agent tool calls (jailbreak, prompt-injection), mapped to OWASP LLM01, with per-call latency recorded.
Model & artifact scanning
Scans models in place without ever executing them — catches malicious pickles and unsafe artifacts before they load.
Model risk scoring
Per-artifact verdict and severity for every scanned model — a clean model passes, a weaponized pickle scores critical.
AI supply-chain security (AI-BOM)
Emits a CycloneDX 1.5 AI-BOM with model components, SHA-256 hashes, licenses, and base-model provenance.
AI red-teaming
Adversarial campaigns with scorecards, pass-rates, and severity-weighted findings — attack packs mapped to the OWASP LLM Top 10 & OWASP Agentic risks.
NL Policy Studio
Plain-English intent compiled into validated firewall, agent-guard, and MCP rules — grounded to real controls, with one-click revert.
Shadow-AI discovery
Discovers the AI tools, agents, and MCP servers running in your environment, tied to a person and a device — and flags unsanctioned MCP servers.
SIEM / SOAR export
Native export to Splunk, Microsoft Sentinel, PagerDuty, Jira, ServiceNow, syslog, and webhook — in CEF/ECS.
Sensor & agent fleet
Register and heartbeat in-environment sensors and enrolled agents, managed from one control plane.
Cross-platform coverage
One control plane, everywhere your AI runs — macOS, Linux, Windows, and Kubernetes.
Compliance transparency
Evidence-linked coverage across OWASP LLM Top 10, OWASP Agentic, NIST AI RMF, and EU AI Act reporting — computed from live signal, not a badge we assert.
Data sovereignty & deployment
Managed SaaS (only the security signals you choose leave) or self-hosted EKS (nothing leaves your environment at all).
Role-based access control (RBAC)
Admin, analyst, and viewer roles across the control plane, with every action written to the append-only, hash-chained audit log.
Scope note: Agies runs as single-org / per-customer deployments today — the depth above is
validated on real software and hardware.