Inspect tools, outputs, PII, policy decisions, and agent trajectories before risky actions reach company systems, with scanners updated as new agent threats emerge.
Scan tool definitions at registration for risky descriptions, hidden instructions, prompt injection attempts, and suspicious patterns.
Inspect agent behavior in real time
Inspect tool output, PII, intent drift, and policy context before results feed the next model step.
Give security the evidence to act
Send security findings to dashboards, audit logs, and SIEM-ready exports with the context needed to reconstruct the event.
Frequently asked questions
ToolGuard looks for tool poisoning, prompt injection, output manipulation, data exfiltration, privilege escalation, destructive actions, and resource abuse. AgentGuard monitors session-level behavior for manipulation and task drift.
ToolGuard sensitivity can be set globally or per connector. Policies can include tool, resource, identity, client, network, OAuth, and runtime conditions.
Security events appear in the Security dashboard and audit logs. Audit logs can also export to S3 for SIEM ingestion.
Docs list typical 50-100ms inference times for ToolGuard scans, with sensitivity settings global or per connector.
Tool List Guard scans definitions at registration. Tool Call Guard and Tool Intent Guard inspect runtime activity around MCP calls. AgentGuard monitors the session trajectory when session scanning is enabled.
Runlayer includes PII detection for common sensitive data types, with configurable scan direction and custom rules for organization-specific patterns.
Security findings work alongside policy. Teams can combine ToolGuard, PII detection, identity, client, connector, tool, resource, and runtime conditions.