Home / Topics / For Security Engineers
For security engineers

Your stack watches the endpoint and the network. It doesn't watch what the agent does.

An agent runs with your credentials, reads your files, and calls your tools — inside your trust boundary, where EDR, DLP, and identity see a normal session. Crawdad gives you the missing layer: runtime enforcement of what each agent is allowed to do, containment when something goes wrong, and a verifiable record of every decision. On the device, before the action.

Run a runtime-security evaluation → Run the attack simulation →

Crawdad produces a runtime enforcement signal and evidence trail the rest of your stack can consume.

Protect agent tool use, prevent data loss, produce investigation evidence.

Your problem isn't detecting a known bad file. It's an agent, acting with real authority, steered by content it trusted, doing something it shouldn't — and you having no control point at the action and no record afterward. Crawdad is that control point.

Enforcement at the action, by identity

Bound each agent to its job (tools, data, effects) with a charter enforced on the observed action, on the wire. Out-of-scope is blocked, and the block names the axis.

Containment on demand

Opt a device into an OS-level default-deny egress lock (pf/iptables) that persists across a process kill; the opt-in Maximum tier runs the agent in a sealed VM. Fail-closed by default.

Credentials made useless if stolen

The real key never enters the agent's environment; a leaked placeholder authenticates nowhere.

Evidence you can hand to an auditor

A signed, hash-chained log verifiable independently — no network, no vendor service, no secrets from the machine.

Proof you can run

A public, reproducible benchmark of 497 real attacks, misses included.

What Crawdad covers, and what it doesn't

Crawdad governs the agent-action path. It doesn't replace your EDR/XDR/SIEM, DLP, IAM, secrets management, or sandboxing — it covers the layer they weren't built for, and produces a runtime enforcement signal and evidence trail the rest of your stack can consume.

Run a runtime-security evaluation → See the architecture →

Free tier, every feature. One command, one env var, no code changes.