On-premises AI security with local-first architecture. Zero-knowledge telemetry. Air-gap capable. Crawdad is designed from the ground up to support the requirements of regulated environments — not retrofitted after the fact.
Audit log — immutable, Merkle-chained event trail for every inspected request
Crawdad runs as a local proxy on each device. Raw content — prompts, responses, documents — never leaves the machine by default. Metadata-only telemetry (counts, categories, verdicts) egresses by default; raw content never does. Telemetry depth is customer-governed. The architecture is designed to satisfy the data-residency and access-control requirements that regulated industries demand, without requiring you to trust a third-party cloud with sensitive content.
Raw content never leaves the device by default. Inspection, detection, and enforcement all happen on-machine. Metadata-only telemetry egresses by default; content does not.
Metadata-only telemetry by default. The fleet console sees detection counts and posture signals — never raw prompts or responses.
Fully functional with no outbound connectivity. Detection, enforcement, and audit logging operate entirely offline.
Merkle-chained event trail. Each entry is cryptographically linked to its predecessor — tampering breaks the chain and is detectable.
Policy floors are cryptographically signed. Local users cannot silently lower enforcement thresholds set by the organization.
Every deployment keeps raw content on-device. The architecture is designed to support the compliance frameworks your industry requires — without asking you to trust a third-party cloud.
PHI never leaves the device by default. Crawdad's local-first architecture is designed to support organizations working toward HIPAA compliance — inspection and enforcement happen on-machine. Metadata-only telemetry (counts, verdicts) egresses by default; protected health information is never included in telemetry.
Architected for environments governed by GLBA, SEC recordkeeping, and financial data protection requirements. The zero-knowledge model means sensitive financial data stays on the institution's own infrastructure. Immutable audit logs support recordkeeping and examination readiness.
Federal, state, county, and local agencies face strict data sovereignty requirements. Crawdad's air-gap capability and on-premises deployment model are designed to support environments where data must remain within sovereign boundaries — no external cloud dependency required.
Operational technology environments cannot tolerate external data flows. Crawdad runs fully air-gapped with no outbound connectivity requirements. Designed to support organizations aligning with NERC CIP and critical infrastructure protection frameworks.
Insurance organizations handle sensitive policyholder data across underwriting, claims, and actuarial workflows. Crawdad's architecture is designed to support compliance with state insurance data security regulations and NAIC model laws — content stays local, audit trails are immutable.
The Fleet Console gives security teams centralized visibility across every deployment — detection trends, posture signals, policy status — while raw content remains on each device. Multi-site, multi-region, or fully air-gapped: the same architecture scales.
Fleet Console — centralized management, zero-knowledge telemetry
Per-site dashboard — detection trends and agent activity
Multi-layer detection pipeline. Built in Rust. 2,988 automated tests across 26 crates. Zero-knowledge by default — raw content stays on the device, metadata-only telemetry unless air-gapped.
AndrewSispoidis/contemporary-agent-attacks →
CC BY 4.0 · 497 attacks · 1,172 benign negatives · 22 categories
Talk to us about deploying Crawdad in your regulated environment. We’ll walk through the architecture, the deployment model, and how the controls map to your compliance requirements.