AGENTGUARD ENTERPRISE

Control the full agent runtime.

Control risk before and after LLM and tool execution with sanitization, degradation, approval, or denial.

PROTECTED OBJECTSCover the complete context of agent action
  • Agents and subagents
  • Identity and delegation
  • Data and memory
  • Tools and MCP
  • External action and production systems
INTERACTION BOUNDARY RUNTIMELIVE CONTROL
AGENTGUARDTRUST BOUNDARY
  1. 01Agents and subagents
  2. 02Identity and delegation
  3. 03Data and memory
  4. 04Tools and MCP
  5. 05External action and production systems
ALLOWREDACTAPPROVEDENY
ENTERPRISEAgentGuard Enterprise
OPEN SOURCEAgentGuard Community
FRAMEWORKS

LangChainMicrosoft AutoGenOpenAI Agents SDKLangGraphLlamaIndexDifyOpenClaw

CONTROL POINTSLLM · Tool · Memory
DEPLOYMENTInside the enterprise boundary

RUNTIME ARCHITECTURE

Agent Execution and Control Topology

From task identity to external action, AgentGuard tracks data, authorization, and action impact across the complete execution path

AGAgentGuardAgentGuard Interaction Boundary Runtime
BUSINESS INTENTEXTERNAL ACTION
Select a protected object
01Task & identity
02Agent orchestration
03Context & reasoning
04Tools & execution
05External action
AGENTGUARDInteraction Boundary RuntimePolicy, context, and evidence stay attached across the execution trace
  1. G1LLM Before / AfterReasoning boundary
  2. G2Tool Before / AfterTool boundary
  3. G3Memory WritePersistence boundary
  4. G4Commit BoundaryCommit boundary
DataProvenance and lineage
AuthorizationPrincipal and delegated scope
Action impactCapability, environment, consequence

UNIFIED SECURITY INFLUENCE ENGINE

Control behavior, reasoning, and data chains

Understand action composition, task intent, and data propagation together at every interaction boundary

Data flow
ProvenanceClassificationDestinationsRetention
Authorization flow
PrincipalCapabilityScopeDelegation and expiry
Action impact
ReadCreateModifyExecuteCommit
AgentGuardUnified Security
Influence Engine
Contextual joint evaluation
Minimum necessary control
ALLOWREDACTRECHECKSANDBOXAPPROVALDENY
What it tracks

Task intent · Propagation lineage · Target boundary · Policy constraints

Why it differs

Risk emerges from the combination of three flows, not one label

How it shapes the decision

Produce an explainable allow, repair, recheck, sandbox, approval, or denial

View technical evidence

Task intent, propagation lineage, target boundary, and policy constraints are evaluated in one boundary state

DIRECT · SEMANTIC · CONTEXTUAL · DECLASSIFICATION

RUNTIME SECURITY CONTROL

Intervene before risk becomes impact

Simulate real tasks and see how AgentGuard preserves business capability while controlling high-impact action

AGAgentGuardRuntime Intervention Simulator
Deterministic simulation
Business taskGenerate a renewal analysis and send a management brief to an approved adviserExecution path · CRM → Contract data → LLM → Report → External adviser
AgentGuard Interaction Boundary Runtime
DataAuthorizationAction impact

COMMUNITY PRODUCT SURFACES

From policy to audit.

See runtime traffic, policy configuration, approval, and audit. Enterprise adds deployment and integration support.

AgentGuard Community runtime monitoring interface
Community Edition interface

Runtime traffic and decisions

Inspect tool calls, policy matches, and decisions by session.

View original ↗

EDITIONS

One foundation. Two ways to deploy.

Community provides the open runtime-security foundation. Enterprise supports organization-wide deployment and continuous security operations.

Open source · GPLv3

AgentGuard Community

A self-managed edition for developers and researchers.

  • Public framework adapters
  • Four runtime hooks
  • DSL policy rules
  • Visual configuration
  • Runtime audit
  • Plugin extensions
View Community Edition ↗
Enterprise delivery

AgentGuard Enterprise

For organization-wide deployment, integration, and continuous security operations.

  • Private deployment support
  • Central policy and audit integration
  • Custom adapters
  • Custom policies and safety models
  • Continuous validation and technical support
Join the waitlist

INTEGRATION & DEPLOYMENT

Enforce inside the trust boundary.

Connect through hooks, sidecars, or gateways. Keep policy and evidence private.

ENTERPRISE TRUST BOUNDARYSECURITY CONTROL LAYER
Policy, traces, and evidence stay in your environment
01AGENT WORKLOADS & EXECUTION
Agent frameworksSDK · Sidecar · Gateway
AGENTGUARDAgentGuard Runtime

Continuous control before and after model and tool execution

  1. 01Pre-execution checks
  2. 02Runtime protection
  3. 03Post-execution audit
Models · Tools · MCP · DataPrivate Control Plane
01Application embedded

Hooks preserve full runtime context.

02Infrastructure enforced

Gateways centralize tool and data control.

03Privately operated

Keep policy, traces, and evidence private.

WORKS WITH YOUR SECURITY STACK

Add agent-aware runtime context

AgentGuard complements existing security systems with context for the full agent action

IAMStatic identity and permissionsTask context, delegation chain, and one-time grants
DLPContent and egress channelsDerived-data lineage and multi-step propagation
API GatewayIndividual requestsThe model, tool, and task trace before each request
SIEMEvents and logsDecision evidence, payload change, and business outcome

VERIFIABLE EVIDENCE

Code, models, research.

Set a control boundary for agent runtime.

Share your stack, critical permissions, and deployment constraints through the product waitlist.

  1. Map one real agent workflow
  2. Mark identity, data, and action boundaries
  3. Simulate privilege, egress, or high-impact risk
  4. Review AgentGuard response and audit evidence
  5. Discuss integration and private deployment
Join the waitlistCommunity Edition ↗