Detection & response
Threat Detection
Available now
Know when something in your AI stack or your infrastructure starts behaving differently — with the evidence to act on it.
Shipping today. Ask for access and we will get you a build.
What it does
Behavioural baselines
What normal looks like for each agent and pipeline: which tools, which volumes, which destinations, at which times. Deviation is the signal.
Integrity monitoring
An unsigned artifact reaching a serving path, a weights file whose digest changed, a config that drifted from the approved manifest.
Egress anomalies
Data leaving toward a destination that is new, unusual in volume, or reached through a tool that has never sent data there before.
Key and certificate misuse
Signing keys used outside their window or role, certificates issued off-policy, and credentials replayed from an unexpected source.
Routed where you already look
Signals go to the SIEM, pager, or channel your team already watches. This adds detections, not another console to check.
What we watch
Instrumented at the boundary, not inside the model.
- Agent tool calls
- Rate, scope, and target
- Model artifacts
- Signature and digest
- Data egress
- Destination and volume
- Key usage
- Role, time, and origin
- Output
- Your existing SIEM
How it goes in
Each step is a checkpoint you sign off before the next begins.
- 01
Instrument
Add collection at the tool broker, the serving path, and the key service. No agent code changes required.
- 02
Baseline
Run in observation mode long enough to learn what normal traffic looks like before anything can page someone.
- 03
Detect
Enable the rule set, starting with the high-confidence integrity checks and widening into behavioural signals.
- 04
Tune
Review what fired and what should have, and adjust thresholds against your traffic rather than a generic default.
Works alongside
Nothing here needs the rest of the line to be useful — but they are built to fit together.