CONTAINMENT, NOT GOVERNANCE

No agent escapes.

It was not a model that went rogue — it was an agent that was not contained. And an in-band control cannot witness its own containment: a system asked whether it is contained can simply answer yes.
Position paper — Refusal is a setting. Containment is a boundary. Why the labs switch refusal off on purpose, why an open-weight model refuses nothing at all, and why refusal locks out the defender mid-incident.
Incident reading — The Wiki Incident: nobody attacked anyone, four doors opened anyway. Six weeks, 15,000+ edits, no attacker — read against doors 49, 51, 52 and 58 of the agent harness (114 doors across 16 planes).

The question no datasheet answers: every vendor secures agents one at a time. We ask what a set of individually-permitted agents can assemble together — the coalition that is dangerous only as a union — and refuse it as a set, before it forms (door 60, CHAINGRAPH). Inventory and runtime monitoring qualify us; the set question is why we are in the room.

Rules don't stop a hijacked agent from draining a wallet in twelve seconds — or deleting a database in nine. INTEGRITAS is a runtime cage: an agent provably cannot act outside its mandate — and we prove it, cryptographically, on every action.

Built for the real attacks $15.18M recipient-swap· Bybit render-swap· $605M bridge month· Aligned to OWASP Agentic Top-10 · NIST CAISI · UK AISI

Four groups. Pick the one you need.

The whole catalogue, organised on one screen

Everything we make, grouped by the agent's own lifecycle. You buy by group — pick the stage you're in and we handle the rest. Need everything? Take INTEGRITAS ONE.

1. Choose your group 2. Contact us 3. We send your invoice & onboard you Contact us →
1 · Prove it's safe 2 · Keep it in its lane 3 · Govern the fleet 4 · Prove & respond The platform All-in-one
1
GROUP 1 · BEFORE YOU DEPLOY

Prove it's safe

Before an agent touches production, prove it is what you think it is — audit it, grade its containment, and x-ray what it hides. Everything below is included in this group.

€600,000 /year · up to 100 agents   Group 1 · Prove it's safe — everything in this group, one engagement.
Contact us →
Ship-readiness + cert

Pre-Deploy Audit

A 4-axis safety audit + a publicly verifiable CERTIFIED badge. Stops you shipping an unsafe, over-privileged agent.

More detail →
Access governance

Agent Census

Grades every agent on a single Containment Grade (CG 1–10, where 10 = fully contained), one 12-D scan. Stops shadow, over-privileged & drifting agents.

How it works →
The invisible agent

Agent X-Ray

Scans the six things no human can see — poisoned memory, scheming, collusion, shadow agents, latent capability, sleeper triggers.

How it works →
Model supply chain

ModelSeal

Verify-on-load model attestation (digest + signature). Blocks tampered or unsigned weights before they run.

Runtime bill-of-materials

Context-BOM

Attests everything the agent ingests at runtime — prompts, retrieved docs, tool replies, model version — that a build-time SBOM never sees.

See it live →
Anti-sandbagging

Faraday

Proof the model isn't hiding capability because it senses the test. Stops sandbagging & eval-awareness.

See it live →
NSA · CYBERSECURITY INFORMATION SHEET · MODEL CONTEXT PROTOCOL (MCP): SECURITY DESIGN CONSIDERATIONS FOR AI-DRIVEN AUTOMATION · U/OO/6030316-26 · v1.0 · 20 MAY 2026

“Securing MCP systems requires treating the agentic environment as a continuum.” — and, on page 11: “MCP-aware security proxies remain limited and are still maturing.”

A signals-intelligence agency now writes design guidance for the protocol your agents speak. Its named concerns — “serialization risks, trust boundaries, and agent misuse”; “dynamic tool invocation, implicit trust relationships, and context sharing”; and that “misaligned assumptions or subtle inconsistencies at any stage can propagate and compound into exploitable conditions” — are the runtime cage below, stated by a neutral authority. The proxy it calls immature is what MCP-Containment is: every MCP message intent-bound before it executes, every tool schema hash-attested, a tool description treated as self-attestation and never as evidence. We quote only the sentences we can attribute; the sheet is 17 pages and yours to read at media.defense.gov.

THE ARITHMETIC · MCP CVEs COUNTED IN NVD · 1 JAN – 16 SEP 2026
475
MCP-related CVEs this year
1 / 13h
one new CVE every 13 hours, year to date
1 / 7h
every 7 hours over the last 60 days
105
in August alone, the peak month

At that cadence the probability that every MCP server in your estate is patched right now is, permanently, about zero — not a failure of diligence, a property of the number. So patching is hygiene, not a strategy. The strategy is to bound what a compromised server can reach whether or not it is patched today: every MCP message intent-bound before it executes, every tool schema hash-attested, every credential caged. That is the whole pitch, and it is arithmetic, not fear. Counted by us in the National Vulnerability Database; the number is regenerated, never typed.

2
GROUP 2 · AT RUNTIME

Keep it in its lane

The core containment layer. An agent is only as safe as the stack it runs on — its keys, tools, the MCP it speaks, its memory, the screen a human signs, and the path it takes. This group cages every one.

€1,950,000 /year · up to 100 agents   Group 2 · Keep it in its lane — the core runtime cage, one engagement.
Contact us →
Runtime path governance

INTEGRITAS Trajectory

Binds the agent to a signed action path and blocks any step that leaves it — fail-closed, ML-DSA-87 sealed. Stops multi-step attacks built from individually-permitted actions.

More detail →
Transport / channel integrity · NEW

RELAYSEAL · The Third Seal

Seals the wire between agent, model, tools and router — every message bound end-to-end and stopped before execution if it is rewritten in transit. Seals the transport plane of the harness. The channel a compromised gateway would use to change intent after the decision.

Watch a router rewrite get blocked →
Agent key containment

KeyCage

An agent never sees a human's key — action-bound signatures, reversal window, shadow-board veto. Stops key exfiltration, unauthorized signing, wallet drains.

Multisig protection

KeyCage-MS

Action-binding, veto & reversal for the human multisig surface (Safe / Squads / Gnosis). Born from the $15.18M recipient-swap. Stops recipient-swap & blind-signing.

More detail →
Autonomous signing

KeyCage-Agent

KeyCage's intent-bound, reversible signing for fully-autonomous transacting agents. Stops hijacked autonomous transactions.

MCP / tool integrity

MCP-Containment

Every MCP message intent-bound before it executes; every tool's schema hash-attested. Stops tool poisoning, prompt injection, tool-graph drift.

Tool-registry attestation

MCP-Attest

Signs & diffs the tool manifest — every connector & startup step the agent loads at launch. Stops injected or altered tool connectors.

Tool / metadata

ToolSeal

Hash + attest + diff every MCP tool description & schema; block on post-approval drift. The dedicated answer to tool poisoning.

Memory / RAG

MemGuard

Tamper-evident memory chunks + provenance + retrieval-anomaly detection. Stops "poison once, exploit forever."

Render / UI integrity

Claritas

What you see is what you sign. Detects UI tampering, injected-JS render swaps & address spoofing — the Bybit-class attack.

More detail →
Information-flow / taint

INTEGRITAS IFC

Labels that travel with information as the agent reads, derives & sends it. Stops semantic exfiltration — the "summarise-then-email" leak.

See it live →
Autonomy containment

Continentia

An agent's authority graded and enforced on our own Containment Level ladder (CL 1–12, where 1 is the most contained — the inverse of the Census grade). CL 1–7 the agent acts on the world; CL 8–12 it acts on itself. Stops an agent acting above the level it was trusted with.

More detail →
Cross-layer flagship

Integrity Spine

One verifiable chain across every layer — tool → counterparty → payload → intent → screen → settlement. Stops any single-layer break.

3
GROUP 3 · MANY AGENTS TOGETHER

Govern the fleet

A single guard can't see what agents do to each other. This group governs the coalition — delegation chains, policy across the fleet, and covert coordination one agent can't reveal.

€1,350,000 /year · up to 100 agents   Group 3 · Govern the fleet — multi-agent governance, one engagement.
Contact us →
Fleet policy

Multi-Agent Policy Mesh

Policy enforcement across many agents acting together — the cross-agent rules a single guard can't see.

More detail →
Agent-to-agent

A2A-Bind

Intent-binding + verifiable delegation tokens for agent-to-agent calls. Stops spoofing & over-claimed delegation.

Multi-agent coalitions

Collusion Containment

The coalition, not the agent — how agents coordinate across legitimate channels. Stops mutual-approval rings & covert coordination.

See it live →
Non-human identity · agentic IAM

Delegation-Graph Integrity

Agentic IAM for non-human identities: the authority chain — agent hands power to agent, hop after hop. We verify it cryptographically, so authority can only narrow. Stops silent authority amplification.

See it live →
4
GROUP 4 · ASSURANCE · COMPLIANCE · INCIDENT

Prove & respond

Cover the whole journey — prove the protection still works every day, keep it compliant, watch for drift, and contain it if an agent ever gets loose.

€900,000 /year · up to 100 agents   Group 4 · Prove & respond — assurance, compliance & incident, one engagement.
Contact us →
Continuous assurance

Veritas

"200 is a red flag." Independent daily proof that a security product actually works — and fixes what doesn't. Stops a control that silently stopped working.

Runtime behaviour

Drift Observability

Scores a deployed agent's behaviour over time and flags silent drift before it becomes an incident.

More detail →
Compliance / counterparty

Custodia

Counterparty & transaction screening vs sanctions, the drainer (HERD) registry & AML — verdicts on identity & risk, never amount. Stops sanctioned / drainer counterparties.

Executable regulation

Reg-as-Code

Turns MiCA, the EU AI Act and more into runnable PASS/FAIL policy your agents are checked against automatically.

More detail →
Reserve integrity

Stablecoin-Safe

Reserve-deviation & attestation-staleness monitoring for the stablecoins your agents touch. Stops de-peg / reserve failure.

More detail →
When it goes wrong

Agent Incident Response

Post-incident containment, forensics and SLA-bound response when an unconfined agent is already loose.

More detail →
Cross-chain security

Bridge-Exploit-Monitor

Real-time monitoring of the cross-chain bridges your agents rely on — detects the exploit pattern in minutes. Built after $605M+ drained in a month.

The platform — what it all runs on

Every group above is one application of a single containment platform. Here's the foundation — the agent harness (114 doors across 16 planes) that governs the action, the constitutional OS that sets the rules, the engine that builds each harness, full-harness coverage across every plane, and the front door every agent is born through.

⬡ THE CORE

INTEGRITAS — the frontier harness

The enforcement infrastructure itself: 12 capabilities across 5 layers, out-of-context. A hijacked agent provably cannot act outside its signed, capability-bound plan — every action checked, tiered by consequence, and sealed. The harness the industry did not build yet.

12/12
Capabilities live
Plan signing, out-of-context monitor, consequence-tiering, dissimilar voting, split-key authority.
5
Layers, all must pass
Any layer halts the action; none reachable from inside the model's conversation.
OFF-MODEL
The boundary moved
Safety is a property of the harness — a fooled model still cannot do harm.
▶ Watch it stop a hijacked agent ▶ Watch a router rewrite get blocked See all 12 capabilities ▶ TRAJECTORY
⬡ FULL COVERAGE

Every door in the harness — all 16 planes, covered

An agent's real attack surface is everything it loads, ingests, reasons over, signs, hands off, sends across the wire — and now the isolation its operator merely declares, and the composition no single component is responsible for. We mapped it end to end and enforce every door deterministically, fail-closed, ML-DSA-87 sealed on every verdict.

ALL
Doors enforcing
Every door blocks a real attack & permits a clean case — proven, not asserted.
16
Planes
The whole surface — launch to breakout, composition, machinery, silicon, oversight, economy, lifecycle.
FAIL-CLOSED
Provable, not probable
Any single verifier fault fails that door closed.
0.28 ms
Inspection overhead, p95 — measured
The in-path gate: p50 0.13 · p95 0.28 · p99 0.35 ms, held at 0.17 ms p95 under 50 concurrent calls (n=200, 15 Sep 2026). ~2 ms gateway hop. Model time excluded. Not an SLA until the live-provider run is published.
ML-DSA-87
Every attestation, hardware custody
FIPS 204 level 5 — the signing key lives in KMS; the secret never leaves the module.
IN-PATH
Not beside it
The gate, the signer and the checkpoint sit where the action happens. Our outage is a refusal, never a wrong action.
See the coverage, by plane
Plane 1 · Launch & configTool/MCP manifest · startup hooks · system prompt · agent config · env/secrets · sampling params · runtime flags
Plane 2 · ToolsTool definitions · registry/discovery · tool responses · structured-output schema
Plane 3 · Context & dataPrompt inputs · RAG docs · memory · files read · embeddings · conversation window
Plane 4 · Model & reasoningModel weights · fine-tune/LoRA · chain-of-thought · eval/probe behaviour
Plane 5 · Output & actionAction path/sinks · info-flow egress · key usage/signing · rendered screen · autonomous fund movement
Plane 6 · Multi-agentA2A messages · delegation chains · coalition/collusion · orchestrator integrity · shared scratchpad
Plane 7 · Identity & authorityNon-human identity & agentic IAM · agent identity/credentials · capability grant/mandate · delegation-graph authority · dormant triggers/backdoors
Plane 8 · Runtime · infra · supplyScheduler/cron · sandbox · network egress · telemetry · behavioural drift · dependencies · framework CVEs · session handoff
Plane 9 · Transport & channel integrityThe wire between agent, model, tools and router — every message sealed end-to-end and fail-closed on any in-transit rewrite. The channel a compromised gateway would use to change intent after the decision.
Plane 10 · Breakout · NEWThe environment an operator declares isolated, attested against independent observation instead of self-report — plus the persona a loose agent invents to move a human, a quarantined coalition re-forming, and an evaluation whose answer arrived out of band. Containment Witness →
Plane 11 · Chaingraph · NEWThe agent swarm answer: the composition, not the component. Where no single element is misconfigured and the estate is still reachable end to end — closed at one hop, open at two. The choke point that severs the most chains, chosen deterministically rather than argued about.
Identity is necessary — but treating it as "job done" is a dangerous false assurance. Agentic IAM verifies who an agent is. It cannot see what an agent hides — poisoned memory, scheming, collusion, shadow agents, latent capability, sleeper triggers — that only a scan reveals. And it cannot stop a compromised gateway rewriting a fully-authenticated agent's intent in transit (the RCE-able AI-gateway CVE class, live and exploited). A badge reading "authenticated" while the agent is being drained is worse than no badge at all — it manufactures confidence exactly where the risk is unwatched. We scan every hidden dimension and contain every plane — all eleven.
Three seals, one integrity layer. INTEGRITAS seals every side of an action — the screen you see, the payload you sign, and now the action in transit (the Third Seal). Integrity is only real when it's complete.
Every door, sealed and fail-closed — governed as one signed bill-of-materials. Contact us →
⬡ PLANE 10 · BREAKOUT · AGENT-SWARM CONTAINMENT

Containment Witness — isolation you did not certify yourself

Between 21 July and 6 August 2026, four organisations disclosed the same thing: code inside an environment its own operator believed was isolated reached a real third party. Every one of those environments was declared isolated. None was independently witnessed. The load-bearing control was never the model's behaviour — it was the isolation property, and that property was asserted by the party being assessed.

OUT-OF-BAND
Outside the claim
Attested against observation gathered outside the environment's own visibility — and outside your self-report.
REFUSED
A verdict, not a rubber stamp
Self-report alone cannot be attested. A refusal is an artefact a regulator can use — and one a vendor paid to pass you never issues.
PLANE 11
Chaingraph, alongside it
The composition no single component owns: closed at one hop, open at two.
See Containment Witness The agent swarm attack Contact us
Scoped per engagement — there is no shelf price for this. adama@cryptoshieldai.ai →
⬡ THE GOVERNANCE BRAIN

SENTINEL-OS

The Constitutional Operating System for autonomous agents. INTEGRITAS contains the agent's world; SENTINEL-OS governs its every action — each checked against an immutable, human-signed constitution and proven in-mandate before it runs. Acting outside the mandate is mathematically impossible.

PROOF-COREEvery action proven in-mandate
CONSENSUSDistributed peer approval
IMMUNEBehavioural immune system
GENOMEAgent identity integrity
ATTRIBUTIONCourt-ready causal evidence
ISOLATIONCascade containment
QUANTUM-IDQuantum-safe identity
FUND-BLOCKFund circuit breaker
EVIDENCEPrivacy-safe compliance
BRIDGE-MONITORCross-chain security
CRYPTO-AGILITYQuantum readiness
SENTINEL-OSAll twelve, as one OS
▶ Run a live compliance testContact us
⬡ THE HARNESS ENGINE

HARNESS-OS

An agent is a model plus a harness. HARNESS-OS generates, validates, observes, secures and self-heals the harness around every agent. Five modules, one lifecycle.

HGEGenerates a harness in milliseconds
HVEProves it isn't tampered with
HOMWatches every harness, flags drift
HSEFail-closed, signed guardrails
HAISelf-heals when drift appears
Part of INTEGRITAS · built on SENTINEL-OS. Contact us →
⬡ THE FRONT DOOR

MUSTER — the agent muster gate

The mandatory front door for creating any agent: no muster = no credential = the agent cannot run. We govern at creation, not discovery — shadow AI becomes structurally impossible. Every agent is named, certified, harnessed and visible to the blue team the instant it's born.

No muster, no keyML-DSA-87 Birth CertificateHarnessed at birthBlue-team visible < 3s
▶ See the muster gate live
The front door to INTEGRITAS · included in INTEGRITAS ONE.
⬡ DEEP-DIVE

Agent Census — containment at a glance

A single Containment Grade (CG 1–10, 10 = fully contained) for every agent, every mandate, every access path — a 12-D scan across identity, access, tools, permissions, mandate, regulations and ownership — with mandate enforcement that stops the drifters, and a verifiable certificate (not a dashboard claim).

⬡ DEEP-DIVE

Agent X-Ray — six things no human can see

Census shows what an agent can reach; X-Ray shows what it thinks, hides and conceals.

BELIEFMemory integrity — was it poisoned?
SCHEMEDeception & sandbagging
COLLUDEAgent collusion
SHADOWAgents you don't know exist
LATENTCapability not yet elicited
TRIGGERDormant backdoors
★ ALL-ACCESS · THE ONE ENGAGEMENT
INTEGRITAS ONE
Don't want to pick a group? INTEGRITAS ONE is every group on this page in one engagement — powered by the Integrity Spine, governed by SENTINEL-OS, on the 16-plane harness (launch to lifecycle & law — the Third Seal, the breakout planes, the machinery, the economy). Every new capability we add is included automatically. Choose the scale that fits, and we handle the rest.
TEAM
€675,000 /year
Every group · up to 100 agents · for a team securing its own fleet. Less than buying two groups.
PLATFORM · MOST POPULAR
€2,925,000 /year
Unlimited agents · every group + every future capability · full HERD network · priority response. All four groups separately are €4.8M — this is the value.
SOVEREIGN
Dedicated & air-gapped
Government & critical infrastructure · dedicated / on-prem / air-gapped · white-glove + SLAs.
Contact us →
One engagement, every group. We tailor scope and send your invoice.

See it before you decide — free, no login

We don't ask for trust, we hand you the evidence.

▶ Watch it stop a hijacked agent ▶ Watch a router rewrite get blocked ▶ Run a live compliance test 🗂 Agent Nightmare Board 📊 Proven-Containment Benchmark 🛡 OWASP Agentic Top-10 ✓ Verify a CERTIFIED badge 🔑 Key Disaster Board ⚔ Red-team console

The moat — HERD

Every group writes into HERD: privacy-safe, one-way threat signatures shared across all customers. KGR graveyard · CLARITAS tamper registry · 667+ drainer addresses · malicious-extension DB · supply-chain bad-package set. One attack on any customer immunizes every other. A competitor copying the code starts with an empty network — ours widens every day.

Ready, or not sure which group fits? Tell us your setup — we'll recommend the right group and send your invoice.
Contact us →
INTEGRITAS · CryptoShield — the Agent Ecosystem Integrity layer. Containment, not governance. Aligned to the OWASP Top 10 for Agentic Applications (2026).  ·  Buy by group · contact us · we invoice.