Most agent-security tools chase the enterprise. Crawdad is built for the MSP.

Your clients are running AI agents right now, with real credentials and file access, and nothing in their stack watches what those agents do. That exposure is your problem, and your opening. Crawdad is the managed agent-security capability you add to the practice you already run: provision, roll out, govern by charter, contain at the operating system, and bill per device, every client from one self-hosted console.

Become a Partner → Download the Partner Brief

Security-first firm running a SOC? See Crawdad for MSSPs → for the monitoring-versus-active-containment story.

Crawdad Fleet Console, manage AI agent security across your client base

Fleet Console, centralized management across your client base

AI agents run with real power inside your clients' environments. Nothing in their stack sees them.

The agent layer is a new attack surface. The MSP who brings the answer first wins the relationship.

A surface nobody covers

AI agents act with real authority, your client's credentials, files, network. When an agent reads a poisoned document, it follows hidden instructions silently. EDR, DLP, firewalls, and identity tools don't see agent-layer behavior. This is a net-new attack surface.

Your clients are already deploying

AI agents are moving from pilot to production across every industry. Regulated clients are asking who secures them. The security buyer is looking for answers, the MSP who arrives first with a real one defines the category.

You own the security relationship

Your clients already trust you with their endpoints, their networks, their identity. Agent security is a natural extension, and a new recurring service line layered on top of the relationship you've already built.

Built for the way you actually deliver. Provision, roll out, govern, bill.

Most agent-security tools chase the enterprise. Crawdad is built for MSPs serving many clients, including regulated ones, on an architecture where nothing leaves the client's machine. The multi-tenant model, the rollout, the governance rollup, and the billing are part of the product, not services you assemble.

Provision

A client in one call

Create a client organization with its own scope, default group, and reusable enrollment key. Each client is an isolated subtree with role-based access, so an operator sees only the clients they are granted.

Roll out

A fleet with one key

One minted enrollment key returns a ready-to-run package: the enroll command, the unattended installer invocations, and the CA fingerprint pin. Devices self-enroll with no per-device signing. Push it through the RMM or MDM you already run.

Govern

By charter, per client

A charter declares what a client's agents are for: which tools, which data, which effects. Crawdad judges the action an agent takes, not the intent it claims, so the identical request is allowed for one agent and blocked for another. Author a template once, share it across clients, and it governs at the wire on their devices; held actions surface in a cross-client review queue you resolve from the console.

Bill

$4.99 per device

Metered billing at $4.99 per governed device per month (launch pricing, revisitable) through Stripe usage records, counted from the real device inventory. Preview the current period any time; the count is a gauge, so it tracks devices as they come and go.

Roll up

Every client, one view

A consolidated rollup puts per-client device counts, open governance holds, threats this week, and metered cost in one response, plus fleet totals, scoped to what each operator can see.

Trajectory reasoning watches the shape of a whole session and holds a staged compromise for review, the exfiltration whose every single step looked fine. No runtime check catches every composed harm; this catches the staging shape. macOS and Linux run full runtime enforcement. The whole model runs on your own self-hosted console, with each client's content staying on their machines.

Fleet Console, per-client tenancy, centralized policy management
Crawdad Dashboard, real-time detection trends, agent activity

Fleet-scale agent security. Every client. One console.

Deploy Crawdad across your client base with one command per endpoint. The self-hosted Fleet Console gives you per-client tenancy, centralized policy, detection trends, and governance rolled up per client and across every client, while raw content stays on each client's machine.

  • Per-client tenancy and isolation, enforced by the scope model
  • Governance rolled up per client and across clients: charter decisions, held actions, threats
  • Charter templates authored once and distributed to a client's devices
  • One-command deployment per endpoint, raw client content never leaves their machines by default
  • Each client gets their own dashboard

One deployment. Every request inspected.

Your client's machine, raw content stays local
🤖
Client's Agent
any framework
Crawdad
inspects every request
🧠
AI Model
any provider
✓ prompt injection ✓ credential leaks ✓ data exfiltration ✓ indirect injection

Crawdad sits between every agent and its model on the client's machine. One environment variable routes traffic. Raw content never reaches the cloud, or you.

That env var is cooperative. Enforce makes Crawdad the only way out.

Pointing an agent at the proxy is a door the agent can decline, and a compromised one may try another route. Monitor is the default and a stock device is byte-for-byte unchanged. Move a client into Enforce, from the console and pinned fleet-wide, and the operating system itself makes Crawdad the only path off the machine. All opt-in, all proven on real hardware.

Enforce · the OS egress lock

Rolled out and pinned per client

Enforce installs a persistent OS default-deny egress lock (pf on macOS, iptables on Linux). A governed agent reaches only the Crawdad proxy path; everything else, including UDP/QUIC, is denied by construction. Set it from the console and pin it across a client's fleet.

  • The lock persists across a kill of the Crawdad process; the boundary doesn't vanish if the enforcer dies.
  • Proven against a live Linux kernel: default-deny to-any, UDP/QUIC, kill -9 persistence, clean removal; and on macOS pf.
Maximum · sealed-VM containment

Containment by construction

The opt-in Maximum tier runs the agent inside a sealed VM (macOS/arm64) whose only network interface routes through Crawdad. Escape is refused at the packet level, not by a deny rule.

  • On real Apple-silicon hardware, an adversarial escape battery was fully blocked and the host filesystem was byte-identical after a guest destruction battery.
  • Liveness-gated, fail-closed: with the VM capability absent it falls back to the Standard egress-lock floor and reports the configured vs in-force tier honestly.
Break-glass · fail-closed

Hard to turn off, on purpose

Because the lock survives a kill, the recovery path is deliberate and deliberately hard to reach, with an audit trail your client can rely on.

  • Break-glass requires root and a device-administrator token, is written to the tamper-evident audit chain, and auto-reverts to Enforce at expiry. The agent can never invoke it.
  • Fail-closed by default: if Crawdad is alive but can't inspect a request, it blocks rather than forwards. There is no degraded fail-open path.

Platform, stated plainly. Full runtime enforcement runs on macOS and Linux; Monitor stays the default, so a stock device is byte-for-byte unchanged until you opt into Enforce. Read the Enforce mode guide →

497 real attacks on a public, reproducible benchmark

The detection engine is measured on this public corpus; on the proxy path the arbiter blocks what it detects. Detection and blocking are named as separate mechanisms, on purpose, and the corpus is open so you can run it yourself. How detection becomes blocking →

497attacks tested
1,669total samples
22attack categories
1missed attack
Every result is published, including the misses. We’re not aware of another vendor in the category that ships a reproducible, clone-and-run benchmark at all. Clone the corpus, run it against us or anyone, and compare. Every number here is reproducible.

Multi-layer detection pipeline. Built in Rust. 3,737 automated tests across 26 crates. Raw content stays on the client's machine by default, metadata-only telemetry by default (none at all when run fully offline).

AndrewSispoidis/contemporary-agent-attacks →

CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories

Channel-friendly. Built for recurring revenue.

Crawdad fits the MSP delivery model. Deploy it, manage it, bill for it.

A new recurring service line

Crawdad is a managed service, not a one-time sale. Layer it into your existing security practice alongside EDR, DLP, and identity. One more line of recurring revenue on top of the relationships you already have.

Additive, not competitive

Crawdad doesn't replace anything in your current stack. It covers the agent layer that EDR, DLP, identity, and firewalls don't see. Additive to your existing offering, no displacement, no rip-and-replace conversations.

First-mover advantage

The AI agent security category is nascent. The MSPs who bring a real answer to their clients now set the standard for how this layer gets covered. First movers define the category, everyone else follows.

The MSPs who secure AI agents first define the category.

Talk to us about becoming a Crawdad partner. We'll walk you through the deployment model, the economics, and how to position agent security to your clients.

Become a Partner → Partner Brief

Get in Touch

Tell us about your needs and we'll follow up.