Your clients are running AI agents right now, with real credentials and file access, and nothing in their stack watches what those agents do. That exposure is your problem, and your opening. Crawdad is the managed agent-security capability you add to the practice you already run: provision, roll out, govern by charter, contain at the operating system, and bill per device, every client from one self-hosted console.
Security-first firm running a SOC? See Crawdad for MSSPs → for the monitoring-versus-active-containment story.
Fleet Console, centralized management across your client base
The agent layer is a new attack surface. The MSP who brings the answer first wins the relationship.
AI agents act with real authority, your client's credentials, files, network. When an agent reads a poisoned document, it follows hidden instructions silently. EDR, DLP, firewalls, and identity tools don't see agent-layer behavior. This is a net-new attack surface.
AI agents are moving from pilot to production across every industry. Regulated clients are asking who secures them. The security buyer is looking for answers, the MSP who arrives first with a real one defines the category.
Your clients already trust you with their endpoints, their networks, their identity. Agent security is a natural extension, and a new recurring service line layered on top of the relationship you've already built.
Most agent-security tools chase the enterprise. Crawdad is built for MSPs serving many clients, including regulated ones, on an architecture where nothing leaves the client's machine. The multi-tenant model, the rollout, the governance rollup, and the billing are part of the product, not services you assemble.
Create a client organization with its own scope, default group, and reusable enrollment key. Each client is an isolated subtree with role-based access, so an operator sees only the clients they are granted.
One minted enrollment key returns a ready-to-run package: the enroll command, the unattended installer invocations, and the CA fingerprint pin. Devices self-enroll with no per-device signing. Push it through the RMM or MDM you already run.
A charter declares what a client's agents are for: which tools, which data, which effects. Crawdad judges the action an agent takes, not the intent it claims, so the identical request is allowed for one agent and blocked for another. Author a template once, share it across clients, and it governs at the wire on their devices; held actions surface in a cross-client review queue you resolve from the console.
Metered billing at $4.99 per governed device per month (launch pricing, revisitable) through Stripe usage records, counted from the real device inventory. Preview the current period any time; the count is a gauge, so it tracks devices as they come and go.
A consolidated rollup puts per-client device counts, open governance holds, threats this week, and metered cost in one response, plus fleet totals, scoped to what each operator can see.
Trajectory reasoning watches the shape of a whole session and holds a staged compromise for review, the exfiltration whose every single step looked fine. No runtime check catches every composed harm; this catches the staging shape. macOS and Linux run full runtime enforcement. The whole model runs on your own self-hosted console, with each client's content staying on their machines.
Deploy Crawdad across your client base with one command per endpoint. The self-hosted Fleet Console gives you per-client tenancy, centralized policy, detection trends, and governance rolled up per client and across every client, while raw content stays on each client's machine.
Crawdad sits between every agent and its model on the client's machine. One environment variable routes traffic. Raw content never reaches the cloud, or you.
Pointing an agent at the proxy is a door the agent can decline, and a compromised one may try another route. Monitor is the default and a stock device is byte-for-byte unchanged. Move a client into Enforce, from the console and pinned fleet-wide, and the operating system itself makes Crawdad the only path off the machine. All opt-in, all proven on real hardware.
Enforce installs a persistent OS default-deny egress lock (pf on macOS, iptables on Linux). A governed agent reaches only the Crawdad proxy path; everything else, including UDP/QUIC, is denied by construction. Set it from the console and pin it across a client's fleet.
kill -9 persistence, clean removal; and on macOS pf.The opt-in Maximum tier runs the agent inside a sealed VM (macOS/arm64) whose only network interface routes through Crawdad. Escape is refused at the packet level, not by a deny rule.
Because the lock survives a kill, the recovery path is deliberate and deliberately hard to reach, with an audit trail your client can rely on.
Platform, stated plainly. Full runtime enforcement runs on macOS and Linux; Monitor stays the default, so a stock device is byte-for-byte unchanged until you opt into Enforce. Read the Enforce mode guide →
The detection engine is measured on this public corpus; on the proxy path the arbiter blocks what it detects. Detection and blocking are named as separate mechanisms, on purpose, and the corpus is open so you can run it yourself. How detection becomes blocking →
Multi-layer detection pipeline. Built in Rust. 3,737 automated tests across 26 crates. Raw content stays on the client's machine by default, metadata-only telemetry by default (none at all when run fully offline).
AndrewSispoidis/contemporary-agent-attacks →
CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories
Crawdad fits the MSP delivery model. Deploy it, manage it, bill for it.
Crawdad is a managed service, not a one-time sale. Layer it into your existing security practice alongside EDR, DLP, and identity. One more line of recurring revenue on top of the relationships you already have.
Crawdad doesn't replace anything in your current stack. It covers the agent layer that EDR, DLP, identity, and firewalls don't see. Additive to your existing offering, no displacement, no rip-and-replace conversations.
The AI agent security category is nascent. The MSPs who bring a real answer to their clients now set the standard for how this layer gets covered. First movers define the category, everyone else follows.
Talk to us about becoming a Crawdad partner. We'll walk you through the deployment model, the economics, and how to position agent security to your clients.