Zero-trust control plane for enterprise AI agents
Control every consequential action your AI agents take
Discover agents, map their effective authority, enforce policy before tools execute, and produce evidence for every decision across cloud, model and framework environments.
CydraLabs is the independent zero-trust control plane that discovers, authorises, monitors and proves every consequential action taken by enterprise AI agents.
Action decision
Illustrative- Agent
- agent://acme/sales-agent
- Delegated user
- j.smith (Sales)
- Tool
- crm.export_contacts
- Target
- Production · Confidential
- Agent Risk Score
- 59 · High
- Inspection
- Personal data detected
Decision
Approval required before execution
Evidence record appended to the hash-linked chain
The problem
Enterprise agents are gaining authority faster than security can see it
Agents are built on many clouds, models and frameworks. Each one can reach tools and data through identities that security teams did not design for them.
Agents act with real authority
Agents now update CRM records, merge code, move money and send email. Each tool call is a consequential action taken on someone's behalf.
Authority is transitive and hidden
An agent's effective reach includes delegated user scopes, MCP servers and every tool those expose. It is rarely written down anywhere.
Controls were built for humans
Identity, approval and data-loss controls assume a person at a keyboard. Agent tool calls often bypass them entirely.
Evidence is missing when it matters
When an auditor or incident responder asks why an agent was allowed to act, logs rarely show the policy, context and approver behind the decision.
Platform
One control plane, shared by every product
CydraShield, CydraGateway and CydraGovern run on the same identity, policy, approval, telemetry and evidence services. Later products will build on them rather than duplicate them.
Identity
Unique agent identities, delegated-user binding and short-lived workload tokens.
Policy
Versioned, deterministic rules evaluated before execution, with default deny.
Approval
Named approvers and single-use, request-bound approval tokens.
Telemetry
Activity metadata and content hashes by default, exported over OpenTelemetry.
Evidence
Every decision appended to a signed, hash-linked evidence chain.
Graph
Users, agents, models, MCP servers, tools, data and actions in one graph.
Core products
Launching with CydraShield, CydraGateway and CydraGovern
Every capability carries a status label: Available, Beta, Preview or Roadmap. Labels describe the current proof-of-concept build.
Security platform for AI agents
CydraShield
Discover every agent, understand its authority and score its risk.
CydraShield capabilities
- Available
Agent inventory and ownership
- Beta
MCP server and tool discovery
- Available
Model inventory (connector data)
- Preview
Live model discovery from provider APIs
- Available
Prompt and activity logging
- Available
Agent identity and permission mapping
- Available
Agent Risk Score (ARS)
Secure agent, MCP and tool gateway
CydraGateway
Decide before tools execute — allow, deny or require approval.
CydraGateway capabilities
- Available
Identity-aware agent gateway
- Available
MCP, API and tool mediation
- Available
Pre-execution policy decisions
- Available
Human approval gates
- Available
Data and secrets inspection
- Beta
Scoped credential handling
- Available
Per-action evidence records
AI governance and compliance
CydraGovern
Turn runtime decisions into continuous compliance evidence.
CydraGovern capabilities
- Beta
AI-system classification
- Beta
Control mapping across frameworks
- Roadmap
PCI DSS control coverage
- Available
Evidence linked to runtime decisions
- Available
Exceptions and remediation tasks
- Available
Audit-readiness dashboards
CydraSOC, CydraDevSec, CydraCloud, CydraWorkforce, CydraKnowledge and CydraVoice are on the product roadmap.
Action control
Every consequential action is decided before the tool executes
CydraGateway puts a deterministic decision point between agents and enterprise tools. Ten steps, the same for every framework and model provider.
Step 1: Receive the proposed action
The agent submits the tool call to CydraGateway with an idempotency key before anything runs.
Step 2: Authenticate the agent
A signed, short-lived workload token is checked for audience, expiry, tenant and replay. Suspended agents are denied.
Step 3: Resolve identity and target
Owner, delegated user, tool, operation, target and environment are resolved. Unknown tools are denied by default.
Step 4: Gather context
Data classification, the latest Agent Risk Score and Agent Security Graph context are attached to the decision input.
Step 5: Evaluate policy
Versioned, deterministic policy is evaluated. A policy engine error fails closed.
Step 6: Inspect content
Parameters and payloads are checked for secrets, personal data and prompt-injection patterns.
Step 7: Decide
Allow, deny or require approval. Deny outranks approval, approval outranks allow, and no matching rule means deny.
Step 8: Approve when required
A named approver issues a single-use, time-bound token bound to the hash of the exact request.
Step 9: Execute with scoped credentials
The action runs with a per-execution credential limited to the target and a short lifetime.
Step 10: Record evidence
The decision and result are appended to the tenant's hash-linked evidence chain and signed.
Agent Security Graph
See the paths from people to agents to data
The graph connects users, agents, models, MCP servers, tools, data and actions, so you can answer questions that inventories alone cannot.
- Which data can this agent reach, directly or transitively?
- What is the blast radius if this MCP server is compromised?
- What is the shortest path from an internet-exposed agent to confidential data?
- How did this agent's access change over time?
Status: Available
Solutions
Start from the outcome you need
AI Security
Find the agents you have, understand what they can do, and reduce their risk
Explore AI SecurityAI Governance
Continuous technical governance, backed by runtime evidence
Explore AI GovernanceCybersecurity
Extend zero trust to the non-human actors in your environment
Explore CybersecurityEnterprise Agents
Deploy agents that act on enterprise systems — with guardrails you can prove
Explore Enterprise Agents
Integrations
Connect the models, protocols and identities your agents already use
Connector adapters share one contract. In this build they run against mock data; live provider APIs are in Preview.
- Preview
OpenAI
Model provider
Discover assistants, models and tool definitions.
Mock adapter Available; live API Preview
- Preview
Anthropic
Model provider
Discover models and agent configurations.
Mock adapter Available; live API Preview
- Beta
Model Context Protocol (MCP)
Tool protocol
Enumerate MCP servers and tools via tools/list.
Generic MCP discovery Beta
- Preview
Microsoft Entra ID
Identity
Map service principals, app registrations and delegated permissions.
Mock adapter Available; live API Preview
- Preview
GitHub
Developer platform
Find agents and tokens in repositories and apps.
Mock adapter Available; live API Preview
Planned integrations
Roadmap- Okta
- Google (Gemini) and open-weight models
- Microsoft Sentinel
- Splunk
- Google Security Operations
- CrowdStrike
- Microsoft Defender
- AWS Security Hub
- ServiceNow
- Jira
- GitLab
- Salesforce
- SAP
- Microsoft 365
- AWS, Azure and Google Cloud
Product names identify interoperability targets and do not imply partnership or endorsement.
Deployment and trust
Designed so security teams can verify it
These are design properties of the current build. They are not certifications or third-party attestations.
Modular deployment
A modular monolith with separate web, API and worker units, packaged as containers and runnable with Docker Compose. Components such as the policy engine are swappable behind stable interfaces.
Tenant isolation
PostgreSQL row-level security on every tenant table, enforced for a non-owner application role. Tenant context comes from the authenticated session, never the request body.
Hash-linked evidence chain
Each evidence record includes the hash of its predecessor and an Ed25519 signature. Verification recomputes the chain and reports any break.
Fail-closed enforcement
If the policy engine or a required detector fails, high-risk actions are denied. Fail-open is an explicit setting limited to read-class actions.
OIDC sign-in
Portal sign-in uses OpenID Connect through a backend-for-frontend session with CSRF protection. Enterprise identity-provider templates are in Preview.
Least-privilege roles
Nine roles from one permission matrix, enforced by the API. Policy authors cannot publish their own policies.
Design-partner programme
We are recruiting a small number of organisations to shape CydraShield, CydraGateway and CydraGovern with us. This section describes the programme; it is not customer evidence, and we do not display customer logos, quotes or results.
What design partners receive
- Early access to the proof-of-concept platform
- Direct input into roadmap priorities
- Joint threat modelling of your agent estate
- Working sessions with the engineering team
What we ask
- Real agent use cases, in a non-production environment
- Regular feedback sessions
- A named security or platform sponsor
- Candid assessment of what does not work
Resources and Academy
Learn, assess and go deeper
Assess your agent risk
An indicative self-assessment using the Agent Risk Score factors.
- In preparation
Documentation
Product and API documentation for the proof-of-concept build.
- Coming soon
Research and AI Security Labs
Agent security research and hands-on labs.
- Roadmap
CydraAcademy
Courses and certifications in AI security and AI governance.
Put a control point in front of your agents' actions
See CydraShield, CydraGateway and CydraGovern working together on a realistic agent estate, or start with an indicative risk self-assessment.