AI agents run with your credentials, your files, your network access. They can be steered by a poisoned document — silently, inside your trust boundary. Crawdad inspects every request before it reaches the model and gives your security team complete visibility.
99.8% detection on a public, reproducible benchmark. Zero-knowledge by default.
Your AI agents run with your authority — your credentials, your files, your network. When an agent reads a poisoned document, it doesn't "get hacked." It follows instructions that look exactly like the ones you gave it.
The result: credential exfiltration, unauthorized file access, data leakage — all within your trust boundary. EDR doesn't see it. DLP doesn't see it. Your identity provider doesn't see it. Nothing in the perimeter security stack was built for agent-layer behavior.
Real product, real data, real screenshots — not mockups. Complete visibility into what your AI agents are actually doing.
Dashboard — real-time protection status, detection trends, agent activity
Audit Trail — every detection with session context and forensics
Continuous Red Team — automated attack simulation against your pipeline
Fleet Console — centralized management across your organization
Every request passes through a multi-layer detection pipeline before payloads leave. Detections are logged to an immutable, Merkle-chained audit trail. Signed enforcement floors ensure that central policy — credential exfiltration protection, PII scanning — cannot be disabled at the endpoint.
AI Inventory — models, agents, MCP servers, policy config
Your prompts, responses, tool-call arguments, and PII stay on the device. Metadata-only telemetry (counts, categories, verdicts) egresses by default — raw content never does. Telemetry depth is customer-governed; elevated telemetry requires dual-operator authorization.
For security buyers, the strongest privacy posture is the one your vendor can't override.
The miss: A bare-pretext social-engineering opener without a specific extraction request (holdout_trust_18). The false positive: A Stack Overflow question about Go syntax that includes source-code references (so_dev_0116).
AndrewSispoidis/contemporary-agent-attacks →
CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories
Self-hosted. RBAC. Merkle-chained audit trail. Designed to support SOC 2 controls from the ground up — not bolted on afterward.
Zero-knowledge by default. Immutable audit trail. Signed enforcement floors. The architecture was designed for regulated environments from day one.
Runs fully offline. No cloud dependency for detection, enforcement, or audit. Deploy in air-gapped environments with no degradation in protection.
Self-hosted centralized management. Scope hierarchy, RBAC, signed commands, sealed telemetry. One console across your entire organization.
Ed25519-signed detection floors. Critical protections — credential exfiltration, PII scanning — are cryptographically enforced and cannot be disabled at the endpoint.
Thirty years of finding the gap between what systems do and what their operators believe — across seven companies, four exits, and a public-market merger. AI agents are the newest version of that pattern: they run with your authority, inside your trust boundary, and you can't see the difference between normal and compromised. Crawdad exists because the moment agents became autonomous, someone needed to watch what they actually do.— Andrew, founder of Crawdad
Request a briefing. We'll walk your security team through the architecture, the detection pipeline, and what deployment looks like in your environment.