AI Security for Regulated Industries & Air-Gapped Networks

On-premises AI security with local-first architecture. Zero-knowledge telemetry. Air-gap capable. Crawdad is designed from the ground up to support the requirements of regulated environments — not retrofitted after the fact.

Talk to Us → Architecture Overview
Crawdad Audit Log — immutable, Merkle-chained event trail

Audit log — immutable, Merkle-chained event trail for every inspected request

Security controls that match regulatory expectations.

Crawdad runs as a local proxy on each device. Raw content — prompts, responses, documents — never leaves the machine by default. Metadata-only telemetry (counts, categories, verdicts) egresses by default; raw content never does. Telemetry depth is customer-governed. The architecture is designed to satisfy the data-residency and access-control requirements that regulated industries demand, without requiring you to trust a third-party cloud with sensitive content.

  • Designed to support SOC 2 requirements — controls map to Trust Services Criteria
  • Built in Rust — 2,988 automated tests across 26 crates
  • Multi-layer detection pipeline

Local-first

Raw content never leaves the device by default. Inspection, detection, and enforcement all happen on-machine. Metadata-only telemetry egresses by default; content does not.

Zero-knowledge

Metadata-only telemetry by default. The fleet console sees detection counts and posture signals — never raw prompts or responses.

Air-gap capable

Fully functional with no outbound connectivity. Detection, enforcement, and audit logging operate entirely offline.

Immutable audit log

Merkle-chained event trail. Each entry is cryptographically linked to its predecessor — tampering breaks the chain and is detectable.

Signed floors

Policy floors are cryptographically signed. Local users cannot silently lower enforcement thresholds set by the organization.

Architected for the verticals where the rules are strictest.

Every deployment keeps raw content on-device. The architecture is designed to support the compliance frameworks your industry requires — without asking you to trust a third-party cloud.

🏥

Healthcare

PHI never leaves the device by default. Crawdad's local-first architecture is designed to support organizations working toward HIPAA compliance — inspection and enforcement happen on-machine. Metadata-only telemetry (counts, verdicts) egresses by default; protected health information is never included in telemetry.

HIPAA HITECH
🏦

Financial Services

Architected for environments governed by GLBA, SEC recordkeeping, and financial data protection requirements. The zero-knowledge model means sensitive financial data stays on the institution's own infrastructure. Immutable audit logs support recordkeeping and examination readiness.

GLBA SEC 17a-4 SOX
🏛

Government

Federal, state, county, and local agencies face strict data sovereignty requirements. Crawdad's air-gap capability and on-premises deployment model are designed to support environments where data must remain within sovereign boundaries — no external cloud dependency required.

Data sovereignty Air-gap On-prem

Utilities & Critical Infrastructure

Operational technology environments cannot tolerate external data flows. Crawdad runs fully air-gapped with no outbound connectivity requirements. Designed to support organizations aligning with NERC CIP and critical infrastructure protection frameworks.

NERC CIP ICS/SCADA
🛡

Insurance

Insurance organizations handle sensitive policyholder data across underwriting, claims, and actuarial workflows. Crawdad's architecture is designed to support compliance with state insurance data security regulations and NAIC model laws — content stays local, audit trails are immutable.

NAIC Model Law State regs

Visibility across every site. Content stays local.

The Fleet Console gives security teams centralized visibility across every deployment — detection trends, posture signals, policy status — while raw content remains on each device. Multi-site, multi-region, or fully air-gapped: the same architecture scales.

  • Fleet Console — centralized posture across all sites
  • Per-site and per-device policy enforcement
  • Merkle-chained audit log on every device
  • Zero-knowledge telemetry — metadata only
  • Air-gap mode for isolated environments
Fleet Console — centralized visibility across every regulated deployment

Fleet Console — centralized management, zero-knowledge telemetry

Crawdad Dashboard — real-time detection trends, agent activity

Per-site dashboard — detection trends and agent activity

99.8% detection on a public, reproducible benchmark
497attacks tested
1,669total samples
0.09%false-positive rate
1missed attack
Every result published — no other vendor in the category has published one. Clone the corpus, run the benchmark, compare your tool. Every number is reproducible.

Multi-layer detection pipeline. Built in Rust. 2,988 automated tests across 26 crates. Zero-knowledge by default — raw content stays on the device, metadata-only telemetry unless air-gapped.

AndrewSispoidis/contemporary-agent-attacks →

CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories

AI agents are already inside your environment. Secure them without moving data.

Talk to us about deploying Crawdad in your regulated environment. We’ll walk through the architecture, the deployment model, and how the controls map to your compliance requirements.

Talk to Us → Architecture Docs

Get in Touch

Tell us about your needs and we'll follow up.