Detection and monitoring are how the category watches for trouble, the smoke alarm, and it earns its place. Crawdad adds the control that acts on the alert: an operating-system egress lock and sealed-VM containment that stop a compromised agent from reaching anything but the Crawdad path. For an MSSP, that is the difference between reselling an alert and operating a control that contains the incident. Multi-tenant, content on-device, one console for every client.
Fleet Console, per-client tenancy and enforcement posture across every client
Nearly everything in the AI-security aisle today watches: it inspects traffic and raises an alert. That is real value and Crawdad does it well. But an alert is not a control. When a client asks what actually happens to a compromised agent, an MSSP wants an answer that ends in contained, not flagged.
Watching for smoke
Putting out the fire
Detection is the foundation, and Crawdad's is benchmarked in the open. Containment is the control you can point to in an incident review. Selling both, from one platform, is the differentiated MSSP offer. See detection and blocking, attack by attack →
Monitor is the default, a stock device is byte-for-byte unchanged. Move a client's devices into Enforce and the operating system itself makes Crawdad the only path off the machine. Everything below is opt-in, pinned per client from the console, and demonstrated against a live kernel, not just asserted. The Linux iptables lock is proven against a live kernel; the macOS pf lock loads its signed anchor and is validated, with live packet-load proof on the 1.7 track.
Enforce installs a persistent OS default-deny egress lock (pf on macOS, iptables on Linux). A governed agent reaches only the Crawdad proxy path; everything else, including UDP/QUIC, is denied by construction.
kill -9 persistence, clean removal; and on macOS pf.The opt-in Maximum tier runs the agent inside a sealed VM (macOS/arm64, Apple's Virtualization framework) whose only network interface routes through Crawdad. Escape is refused at the packet level, not by a deny rule.
Because the lock survives a kill, there is a deliberate recovery path, and it is deliberately hard to reach, exactly the audit story a SOC wants.
Platform, stated plainly. Full runtime enforcement runs on macOS and Linux; Monitor stays the default, so a stock device is byte-for-byte unchanged until you opt into Enforce. Read the Enforce mode guide →
An MSSP lives or dies on isolation. In Crawdad, each client is its own scope subtree with role-based access, so an analyst sees only the clients they are granted. And because the architecture is local-first and on-device, the isolation is structural, not a filter: one client's prompts and responses never leave that client's machines, so they cannot mix in a shared store because there is no shared store of content.
We prove this the honest way: a repeatable, clearly-labelled synthetic environment stands up several fictional customer orgs across real verticals and shows the isolation, posture spread, and rollup end to end. It is watermarked synthetic throughout, never presented as real customers.
The multi-tenant model, the enforcement rollout, the review queue, and the exports are part of the product, not services you assemble. Crawdad rides alongside the tools your analysts already live in.
Create an isolated client scope, then roll out with one minted enrollment key and a ready-to-run package: the enroll command, the unattended installer invocations, and the CA fingerprint pin. Devices self-enroll with no per-device signing. Push it through the RMM or MDM you already run.
Set enforcement per client and pin it fleet-wide. A charter bounds what a client's agents are for, judged on the action taken, not the intent claimed; held actions surface in a cross-client review queue your analysts resolve from the console, releasing a session or keeping it gated.
Every device event lands in a tamper-evident, hash-chained audit log, Ed25519-signed and offline-verifiable with a standalone tool, no network and no secrets from the machine. Verifiable forensics is the report you hand a client after an incident.
Export detection and governance events to your SIEM over Splunk HEC or OpenTelemetry, so agent-layer signal lands where your analysts already work. Bill per governed device at $4.99/month (launch pricing, revisitable) through Stripe metered usage records, counted from the real device inventory.
Trajectory reasoning watches the shape of a whole session and holds a staged compromise for review, the exfiltration whose every single step looked fine. No runtime check catches every composed harm; this catches the staging shape, at a false-positive cost measured at zero on benign multi-step work. The whole model runs on your own self-hosted console, with each client's content staying on their machines.
The detection engine is measured on this public corpus, the local sidecar's full multi-layer ML pipeline running in-line on proxied traffic. On the proxy path the arbiter blocks what it detects. Detection and blocking are named as separate mechanisms, on purpose, and the corpus is open so you can run it yourself. How detection becomes blocking →
Multi-layer detection pipeline. Built in Rust. 3,737 automated tests across 26 crates. Raw content stays on the client's machine by default, metadata-only telemetry by default (none at all when run fully offline).
AndrewSispoidis/contemporary-agent-attacks →
CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories
Containment is a higher-value service than a feed of alerts. Crawdad gives you something to charge for that your clients can feel.
Most of the market resells detection. An MSSP that can say "and here is the control that contained it, at the operating system" has a story the alert-only competitor can't match, backed by proof, not adjectives.
Crawdad covers the agent layer that EDR, DLP, identity, and network tools don't see, and streams its signal into the SIEM your analysts already run. Additive to your SOC, not a rip-and-replace.
Agent security is nascent, and containment is the part most vendors haven't reached. The MSSPs who bring a real control now set the standard their clients measure everyone else against.
For your evaluation, stated plainly: full runtime enforcement runs on macOS and Linux. SOC 2 is architected-for, not certified, and no third-party security audit has been completed. A macOS System Extension for system-wide interception is built and pending an Apple entitlement; until it is granted, protection covers agents routed through Crawdad rather than every process on the machine. We have no customer or production-deployment claims to make in either direction. See the full trust posture →
Talk to us about becoming a Crawdad partner. We'll walk you through the containment model, the multi-tenant console, and how to position active containment against a market that mostly monitors.