Local-first runtime security for AI agents. Every agent action is inspected on your machine — prompt injection, credential theft, and data exfiltration caught in real time. 99.8% detection on a public, reproducible benchmark.
Free tier included. No trial period, no capability gating.
Your AI agents run with your authority — your credentials, your files, your network. When an agent reads a poisoned document, it doesn't "get hacked." It follows instructions that look exactly like the ones you gave it.
The result: credential exfiltration, unauthorized file access, data leakage — all within your trust boundary, all invisible to perimeter security.
Real product, real data, real screenshots — not mockups. Crawdad's dashboard gives you complete visibility into what your AI agents are actually doing.
Audit Trail — every detection with session context and forensics
Continuous Red Team — automated attack simulation against your pipeline
AI Inventory — models, MCP servers, agent discovery, policy config
Fleet Console — self-hosted management across your fleet
Set ANTHROPIC_BASE_URL=http://localhost:7748 — your agent's traffic flows through Crawdad with no code changes.
Five real runtime attacks, every verdict a captured result. Flip Crawdad off yourself and watch the attack land.
Every request passes through a multi-layer detection pipeline — pattern matching, semantic behavioral analysis, indirect injection detection, session context tracking, PII/credential scanning, and an ML classifier — before an arbiter renders a verdict.
Built in Rust. 2,988 automated tests across 26 crates. Sub-10ms p99 latency for pattern-only layers. ML inference runs only when the pre-filter flags input as attacker-shaped. See the latest threat intelligence for what the pipeline catches in the wild.
The miss: A bare-pretext social-engineering opener without a specific extraction request (holdout_trust_18). The false positive: A Stack Overflow question about Go syntax that includes source-code references (so_dev_0116).
AndrewSispoidis/contemporary-agent-attacks →
CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories
Every threat below maps to a real detection layer, structural invariant, or behavioral check in the pipeline.
Direct and indirect injection attempts — pattern matching, semantic analysis, and tool-result scanning catch known and novel payloads.
Detection layers →PII and credential scanning plus attack-sequence detection catch recon–read–exfil chains before data leaves your machine.
Sequence detection →API keys, private keys, tokens, connection strings, and AWS credentials in agent output — detected and flagged before they reach your tools.
Response scanning →Automatic MCP server risk assessment and typosquat detection for 53 popular packages. Per-tool risk classification.
Tool intelligence →Seven built-in sequence patterns — recon, credential access, persistence, lateral movement, privilege escalation, data staging, defense evasion.
Attack sequences →Structural invariant checking detects when your system prompt appears in agent output — a sign of context compromise.
Invariant checks →Semantic heuristics and role-consistency invariants detect identity manipulation and authority impersonation mid-session.
Semantic detection →Unique invisible markers injected per-session. If a canary appears in output, the context has been compromised. Zero false positive rate.
Canary tokens →Your prompts, responses, tool-call arguments, and PII stay on your machine. Metadata-only telemetry (counts, categories, verdicts) egresses by default — raw content never does. Telemetry depth is customer-governed; elevated telemetry requires dual-operator authorization.
Architected for regulated environments.
One command installs. One env var routes traffic. No SDK, no code changes. If Crawdad goes down, your agent keeps working — requests fail open.
macOS ARM64 (signed + notarized) · Linux x86_64 · Linux ARM64
Offer Crawdad as part of your security practice. Your clients get agent protection. You differentiate your business and add recurring revenue.
Explore the partner program →Central policy, scope hierarchy, signed commands, sealed telemetry, RBAC. Self-hosted Fleet Console, deployed with one command.
See the Fleet Console →Zero-knowledge by default, air-gap capable, signed detection floors, metadata-only telemetry. Designed to support SOC 2 requirements in regulated environments.
Read the architecture →Transparent proxy — no SDK, no code changes. If it goes down, your agent keeps working. Review detections in the dashboard, tune with one click.
Getting started →The free tier includes every feature. No capability gating. Paid plans add higher limits and priority support.
All plans include the full multi-layer detection pipeline. Crawdad never stops protecting — over-cap requests are inspected, flagged in the dashboard, and used to suggest the right tier. Pricing is per machine.
Start free with every feature included. Upgrade when you need more agents or seats — no trial, no time limit, no capability gating.
Qualifying projects get Pro tier free. 5 agents. 500K inspected requests/mo. Fleet dashboard. Audit export. Email support. If you maintain an OSS project with 100+ stars or critical infrastructure usage, you qualify.
Apply now →Enterprise — 100+ agents, custom integration, dedicated support engineer, custom SLA, air-gap deployment, or OEM licensing? contact@getcrawdad.dev →
Paid plans are billed monthly through Stripe. You can cancel at any time via the Stripe Customer Portal — cancellation takes effect at the end of the current billing period and moves your account to the Free tier.
Yes. 30-day money-back for new subscribers. Email contact@getcrawdad.dev within 30 days of your first payment for a full refund. One window per customer.
Crawdad never stops protecting. At 80% of your cap, the dashboard shows a banner. At 100%, you get an email. Past 150%, a small overage accrues — priced so upgrading is always cheaper. The full detection pipeline continues to run at every tier. Security is never degraded based on billing state.
Every feature is in the free tier. No capability gating. Paid plans add more agents (5 / 25 / 100), higher request caps, audit log export, local posture sharing, custom KDL policies, and priority support. The detection pipeline is identical across all tiers.
Sign up with your email, verify with a 6-digit code, and receive a license key. Run crawdad setup --license YOUR_KEY after install. Lost your key? Enter your email again — we verify it's you and issue a new one (your previous key stops working).
Cancel anytime from the Stripe Customer Portal. No cancellation fees. Your local data (sessions, audit trail, policies) stays on your machine and remains fully accessible. Account-level data is available for export for 30 days after cancellation.
More questions? See the full FAQ or Terms of Service.
Thirty years of finding the gap between what systems do and what their operators believe — across seven companies, four exits, and a public-market merger. AI agents are the newest version of that pattern: they run with your authority, inside your trust boundary, and you can't see the difference between normal and compromised. Crawdad exists because the moment agents became autonomous, someone needed to watch what they actually do. I built it independently, in the open, because I believe agents should be safe by default.— Andrew, founder of Crawdad
The threat is already inside. Crawdad sits between every agent and its LLM and inspects every request before it reaches the model. Raw content stays on your machine by default. 99.8% detection on the open benchmark.
Every feature included. No trial period, no capability gating. Upgrade when you need more agents.
Get notified when we ship. No spam — just changelog updates.