Crawdad governs each agent by its authorized purpose and judges the action it takes, not the intent it claims, on the machine where the agent runs. Raw content never leaves the device, so there is nothing for a vendor to hold or a breach to reach, and every decision lands in a hash-chained audit an outside party can verify without trusting us. Runs fully offline.
Audit log, tamper-evident, hash-chained event trail for every inspected request
For a review board, the governance question is not what an agent was told to do, but what it actually did, and whether that fits its authorized purpose. Crawdad governs each agent by an operator-declared charter it cannot see or edit, judges the observed action rather than the stated intent, and watches the whole session for staged compromise. Every decision is made on-device and written to the tamper-evident, hash-chained audit trail your team can verify independently.
An operator writes a charter, held outside the agent's control, declaring the agent's real job as an allowlist over three axes: the tools it may call, the data (paths, hosts, recipients) it may touch, and the effects it may produce. Crawdad checks the observed action, so a deceptive stated intent buys nothing, and an out-of-charter action is blocked at the wire with the axis named. The identical request from two agents can get two verdicts, because the charter decides, not the bytes.
A sequence of individually-allowed steps, enumerate then read progressively more sensitive in-scope data then send, can still compose toward harm. Crawdad measures that shape with deterministic signals anchored to resource sensitivity, and gates an on-device reasoner onto the genuinely ambiguous cases. With no local model reachable, a completed staging chain is held for review, never silently allowed. The false-positive cost on ordinary multi-step work is measured at zero. It does not claim to catch every composed harm; it catches staged compromise that carries a sensitivity climb.
Every decision is legible and reviewable. An operator sees the live governance feed and per-session risk from the local dashboard, authors a charter that governs at the wire on the next action, and approves or denies a held action with a real effect on the running engine. Across sites, the self-hosted console rolls governance up per deployment, distributes charter templates that devices load, and surfaces held actions for triage, over the same signed channel every other fleet command uses. Content never leaves the device: only the resource identifier, the axis, the signals, and the verdict travel.
Crawdad runs as a local proxy on each device. Raw content, prompts, responses, documents, never leaves the machine by default. Metadata-only telemetry (counts, categories, verdicts) egresses by default; raw content never does. Telemetry depth is customer-governed. The architecture is designed to satisfy the data-residency and access-control requirements that regulated industries demand, without requiring you to trust a third-party cloud with sensitive content.
Raw content never leaves the device by default. Inspection, detection, and enforcement all happen on-machine. Metadata-only telemetry egresses by default; content does not.
Metadata-only telemetry by default. The fleet console sees detection counts and posture signals, never raw prompts or responses.
Fully functional with no outbound connectivity. Detection, enforcement, and audit logging operate entirely offline.
Hash-chained event trail. Each entry is cryptographically linked to its predecessor, tampering breaks the chain and is detectable.
Policy floors are cryptographically signed. Local users cannot silently lower enforcement thresholds set by the organization.
The Fleet Console gives security teams centralized visibility across every deployment, detection trends, posture signals, policy status, while raw content remains on each device. Multi-site, multi-region, or fully offline: the same architecture scales.
Fleet Console, centralized management, metadata-only telemetry
Per-site dashboard, detection trends and agent activity
Every deployment keeps raw content on-device. The controls map to the frameworks your industry answers to, and none of it asks you to trust a third-party cloud with sensitive content.
PHI never leaves the device. Inspection and enforcement happen on the machine, and metadata-only telemetry (counts, verdicts) is all that egresses, so protected health information is never in it. The controls map to HIPAA and HITECH obligations for the agents handling that data.
Architected for environments governed by GLBA, SEC recordkeeping, and financial data protection requirements. The on-device model means sensitive financial data stays on the institution's own infrastructure. Tamper-evident audit logs support recordkeeping and examination readiness.
Federal, state, county, and local agencies face strict data-sovereignty requirements. Crawdad runs fully offline and on-premises, so data stays within sovereign boundaries with no external cloud dependency.
Operational technology environments cannot tolerate external data flows. Crawdad runs fully offline with no outbound connectivity, which aligns with NERC CIP and critical-infrastructure protection obligations.
Insurance organizations handle sensitive policyholder data across underwriting, claims, and actuarial workflows. Content stays local and audit trails are tamper-evident, mapping to state insurance data-security regulations and the NAIC model law.
The detection engine is measured on this public corpus; on the proxy path the arbiter blocks what it detects. Detection and blocking are named as separate mechanisms, on purpose, and the corpus is open so you can run it yourself. How detection becomes blocking →
Multi-layer detection pipeline. Built in Rust. 3,737 automated tests across 26 crates, mechanically counted 2026-08-22. Raw content stays on the device by default, metadata-only telemetry by default (none at all when run fully offline).
AndrewSispoidis/contemporary-agent-attacks →
CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories
For your review board, stated plainly: full runtime enforcement runs on macOS and Linux. SOC 2 is architected-for, not certified, and we publish the control mapping so your team can evaluate the fit. A macOS System Extension for system-wide interception is built and pending an Apple entitlement; until it is granted, protection covers agents routed through Crawdad rather than every process on the machine. See the full trust posture →
Talk to us about deploying Crawdad in your regulated environment. We’ll walk through the architecture, the deployment model, and how the controls map to your compliance requirements.