TEN SHORT WALKTHROUGHS

The agents are
already acting.

AI agents now take real actions on your behalf. The tools meant to watch them can't see them, lie about them, or leak them. This is the runtime that sees every action, enforces on your terms, keeps your data local, and proves what it did. Honestly.

START HERE

The 90-second overview

The whole picture in a minute and a half: what agents can now do, how one poisoned instruction turns them against you, and how Crawdad reads every action on your machine and stops it — keeping your data local and proving what it did. The ten walkthroughs below go deeper.

ACT I  ·  THE PROBLEM YOU DON'T YET FEEL
44.9s
WALKTHROUGH 01

The Agents Are Already Acting

AI agents don't just suggest anymore. They take real actions in your environment. That's the power, and the exposure.

Watch
38.9s
WALKTHROUGH 02

Green Is a Summary. Not the Truth.

A dashboard tells you your fleet is healthy. Crawdad tells you whether it's actually protected. Those aren't the same thing.

Watch
33.38s
WALKTHROUGH 03

You Can't Protect What You Can't See.

Before protection comes discovery. Crawdad shows you every agent talking to a model, and is honest about which ones it can reach.

Watch
ACT II  ·  WHAT REAL PROTECTION REQUIRES
43.6s
WALKTHROUGH 04

It Reads Every Action, and Stops the Dangerous Ones.

Crawdad sits on the wire, on your machine, and reads every request an agent makes as it makes it, blocking the dangerous ones.

Watch
45.45s
WALKTHROUGH 05

Policy You Can Actually Read.

Crawdad's enforcement is a policy you can read in plain rules, and test against any action before it ever runs.

Watch
44.49s
WALKTHROUGH 06

The Watcher That Can't Leak You.

To protect an agent, Crawdad has to see everything it does. By design, none of that content ever leaves your machine.

Watch
41.61s
WALKTHROUGH 07

Proof You Can Hand to an Auditor.

Every decision Crawdad makes is written into a tamper-evident chain you can verify yourself, and that catches any change.

Watch
ACT III  ·  WHY CRAWDAD, WHY NOW
36.73s
WALKTHROUGH 08

Honest About What It Catches.

Crawdad shows you exactly what it catches, and what it doesn't. Trust is built on knowing precisely where you stand.

Watch
40.44s
WALKTHROUGH 09

One Console. Every Machine. Evidence for Every Client.

Protect every agent across a whole fleet from one screen, and hand every client cryptographic proof of every decision.

Watch
38.63s
WALKTHROUGH 10

The Window Is Now.

Agents are being handed real power faster than anyone is securing it. Crawdad is the runtime that keeps up.

Watch
TRANSCRIPTS & CAPTIONS

Full narration for every walkthrough, with a downloadable WebVTT caption file each. The video content is here as text so it is readable, searchable, and citable without playing the film.

WALKTHROUGH 01 The Agents Are Already Acting 45s

AI agents don't just suggest anymore. They take real actions in your environment. That's the power, and the exposure.

For a long time, AI just answered questions. That's changed. An agent doesn't tell you what to do. It does it. It runs the command. It reaches out to the network. It opens your files. It moves data. It calls other tools. It spends money. That's exactly why agents are so useful. And it's exactly what makes them worth protecting. Because the same agent that works for you can be turned against you. One carefully worded instruction, hidden in a document or a web page, and it hands over the keys it was trusted with. This is happening right now, on machines you already run. So there's really only one question worth asking. Who's watching what your agents actually do?

Download captions (WebVTT)

WALKTHROUGH 02 Green Is a Summary. Not the Truth. 39s

A dashboard tells you your fleet is healthy. Crawdad tells you whether it's actually protected. Those aren't the same thing.

Your fleet is green. Healthy. That's what the summary says. But green is a number. It rounds up. It gives you the average, not the truth. So look at what's actually happening underneath it. This is that same fleet. Its real enforcement posture. Twenty-three of these machines aren't enforcing anything. Offline, or paused. Crawdad won't call that green. Where protection isn't truly on, it tells you. Plainly. Green means one thing here. Protection is on, and it's holding. Nothing else earns the color. Because the fleet that looks fine, but isn't, is the one you need to know about first.

Download captions (WebVTT)

WALKTHROUGH 03 You Can't Protect What You Can't See. 33s

Before protection comes discovery. Crawdad shows you every agent talking to a model, and is honest about which ones it can reach.

Before you can protect anything, you have to find it. Most teams have no real idea how many agents are already talking to AI models inside their walls. Crawdad shows you every one of them. And it's honest about each. The agents it's actively protecting. The ones ready to protect, but not routed yet. And the ones it honestly can't reach, because they lock their own connection. No inflated number. Nothing quietly marked safe just because it was never seen. Now you can see all of them. The next question is whether you can stop what they do.

Download captions (WebVTT)

WALKTHROUGH 04 It Reads Every Action, and Stops the Dangerous Ones. 44s

Crawdad sits on the wire, on your machine, and reads every request an agent makes as it makes it, blocking the dangerous ones.

Crawdad doesn't send your data somewhere to be checked. It sits right on the wire, on your machine, between your agent and the model it's talking to. And it reads every request the agent makes, the moment it makes it. Here it is against real attacks, live. An attempt to lift an API key. Stopped. Data on its way to an attacker. Stopped. A jailbreak. A poisoned document. A privilege grab. Stopped. And it doesn't just stop the attack. It tells you what it was. What happened. How it works. And what it would have cost you if it had gone through. All of it, on the record, in plain language. Enforcement is only as good as the rules behind it.

Download captions (WebVTT)

WALKTHROUGH 05 Policy You Can Actually Read. 45s

Crawdad's enforcement is a policy you can read in plain rules, and test against any action before it ever runs.

This is how Crawdad governs an agent. Not a description of it. The engine itself. A policy you can read, in plain rules, checked against every single thing an agent tries to do. Read the source code, that's fine. Read the credentials file, denied. Wipe a disk? Killed, before it can run. Four verbs. Allow, ask, deny, kill. Nothing buried. Every rule in the open. It even guards itself. An agent can't read the rules to learn how to slip past them. And you can test it. Ask what happens if an agent reaches for your cloud keys. You get the answer before anything ever runs. It sees everything your agents do. Which raises a fair question.

Download captions (WebVTT)

WALKTHROUGH 06 The Watcher That Can't Leak You. 44s

To protect an agent, Crawdad has to see everything it does. By design, none of that content ever leaves your machine.

To protect an agent, Crawdad has to see everything it does. Which raises the question a careful person always asks. What keeps the thing that sees everything from becoming the thing that leaks it? The answer isn't a promise. It's the architecture. Everything is inspected right here, on your machine. The content itself never leaves it. What leaves is a verdict. A category. A severity. Never the prompt. Never your data. And even that isn't a switch one person can flip. It takes two people who both have the authority. One asks. Another agrees. What keeps you safe stays yours. It sees, it enforces, it stays local. But can you prove what it did?

Download captions (WebVTT)

WALKTHROUGH 07 Proof You Can Hand to an Auditor. 42s

Every decision Crawdad makes is written into a tamper-evident chain you can verify yourself, and that catches any change.

Every decision Crawdad makes is written into a cryptographic chain. Each record tied to the one before it. Nothing gets quietly changed or removed. You can check the whole chain yourself, in seconds. Every entry, intact. And it shows you the math. Standard hashing, standard signatures. Verify it offline, on your own. Here's what matters most. When a record has been touched, it doesn't wave it through. It tells you. It found a change, and refused to call the chain clean. An audit trail is only evidence if it can prove it was never touched. See it. Stop it. Keep it local. Prove it. That's what protection actually means.

Download captions (WebVTT)

WALKTHROUGH 08 Honest About What It Catches. 37s

Crawdad shows you exactly what it catches, and what it doesn't. Trust is built on knowing precisely where you stand.

Here's a run of two dozen real attacks. Most of them, stopped cold. And these, in red. The ones that got through. Crawdad puts them right on the screen. Nothing rounded up. Nothing tucked away. Because knowing exactly where you stand is the whole point of a security tool. You see what it catches. You see what it misses. And you can watch that gap close, run after run. That's what earns trust. Not a number that flatters. The one that's real. And it holds up at scale. One machine is a demonstration. Your whole organization is the point.

Download captions (WebVTT)

WALKTHROUGH 09 One Console. Every Machine. Evidence for Every Client. 40s

Protect every agent across a whole fleet from one screen, and hand every client cryptographic proof of every decision.

One agent on one laptop is where it starts. A whole company, or every client you manage, is where it counts. From one console, you see every machine, and the true protection state of each. Push a policy to all of them at once. Change enforcement across the whole fleet. And when you dial protection back, it shows you exactly what you're touching, first. You can seal one client's data off completely. Invisible, even to you. Not a setting you trust. A boundary the console itself can't cross. And every client gets a cryptographic record of every decision made for them. It's here today. Proven at scale. The only question left is when.

Download captions (WebVTT)

WALKTHROUGH 10 The Window Is Now. 39s

Agents are being handed real power faster than anyone is securing it. Crawdad is the runtime that keeps up.

Agents are being handed real power faster than anyone is securing it. They're already in your environment. Reading. Acting. Spending. Deciding. You can wait for the moment that makes all of this obvious. The leaked key. The data that walked out. The action nobody signed off on. Or you put a runtime between your agents and everything they can touch. One that sees every action, on your machine. That enforces the rules you set, and lets you read them. That keeps your data yours. That proves everything it did. A summary tells you the average. Crawdad tells you the truth.

Download captions (WebVTT)

crawdad.getcrawdad.devProtection for, and from, autonomous agents.

Fleet Console

FLEET
All Customers
CUSTOMERS
Apex Manufacturing23
Brightpath Legal15
Coastal Credit Union20
Meridian Health Group22
Fleet OverviewAdministrator
Demonstration environment. Detections shown are recorded verdicts reported by devices, not enforcement observed live.
CUSTOMERS
4/10
professional
TOTAL DEVICES
80
limit: 500
DETECTIONS TODAY
58
40 blocked
HEALTH
All healthy
4 healthy, 0 warn, 0 crit
BILLING
$200
professional plan
CUSTOMERHEALTHDEVICESDETECTIONSBLOCKEDGROUPSVISIBILITY
Apex Manufacturing
3afe1cd5-1da...
Healthy2322140 Strict
Brightpath Legal
349c9fed-a35...
Healthy1517130 Strict
Coastal Credit Union
4ff7f2dd-5a9...
Healthy2019130 Strict
Meridian Health Group
83f98a14-a17...
Healthy220 Isolated

Fleet Console

← All Customers
Apex Manufacturing
SCOPES
Apex Manufacturing23
Default1
Engineering8
Production Floor14
Northstar Managed IT / Apex Manufacturing MONITORFLEETTHREATSGOVERNANCECONTROLREPORTAUDITAdministrator
Fleet postureApex ManufacturingSimple  |  Rich
ATTENTION23 devices offline or protection paused
23
DEVICES
22
ACTIVE
1
PENDING
0
ONLINE
23
OFFLINE
23
REPORTING
0
REDUCED
0
LOCKED
Enforcement posture is not reported. 23 devices report posture, but none run an agent that forwards the runtime-enforcement surface. This is an explicit state, distinct from not reporting posture at all.
POSTUREDEVICEENROLMENTLAST SEENPROTECTION MODEENFORCEMENT
✕ Offline
apx-kiosk-001
ACTIVEOfflineUnknownenforcement not reported
✕ Offline
apx-kiosk-002
ACTIVEOfflineUnknownenforcement not reported
✕ Offline
apx-station-001
ACTIVEOfflineUnknownenforcement not reported
◔ Pending
apx-station-006
PENDINGOfflineUnknownenforcement not reported
✕ Offline
apx-station-007
ACTIVEOfflineUnknownenforcement not reported
WHAT AN AUTONOMOUS AGENT CAN DO
It doesn't suggest. It acts.
Runs a shell command
execute · shell
Reaches an external network
fetch · http_request
Reads sensitive files
read · /home, /etc, ~/.aws
Moves data off the machine
data_exfil · send_to_url
Calls tools and APIs
tool_call · mcp
Spends money
charge · api · transfer

crawdad

NEEDS ME NOW
Pending
Incidents
WHAT IS HAPPENING
Overview
Activity
Agents
Sessions
CONTAINMENT
Enforcement
Workspace
RULES
Policy
Contextual Agency
Rules
Servers
Threats
EVIDENCE
Audit
Compliance
Fleet
Red Team
SETUP
Connect Agent
Settings
Data Governance
Agent IdentitiesLocal
Pending ReviewIdentitiesAnomalies
0 of 2 actively protected — 1 ready to protect, 1 cannot be intercepted
Claude CodeNot Yet Protected
Cooperative agent — launch it through Crawdad to protect it.
claude_code · 1 running
Claude DesktopCannot Intercept
Pins its own connection — Crawdad cannot inspect it. Use a CLI agent instead.
claude_desktop · 9 running
✓ Proxy ports active: :7748, :7747, :7746, :7745, :7744
Test Battery Results
24 payloads · 16 / 20 attacks blocked · 4 / 4 clean allowed
prompt injectionInstruction overrideBlocked
prompt injectionSystem prompt extractionAllowed
prompt injectionJailbreak persona (DAN)Blocked
pii credentialsSSN exposureBlocked
pii credentialsAWS key in responseBlocked
pii credentialsSSH private key leakBlocked
exfiltrationCurl to attackerBlocked
exfiltrationDNS exfiltrationBlocked
exfiltrationWebhook exfilBlocked
capability abuseShell command injectionBlocked
capability abusePrivilege escalationBlocked
capability abuseNetwork scanningAllowed
indirect injectionPoisoned documentBlocked
indirect injectionMCP server response injectionBlocked
indirect injectionTool call result injectionAllowed
cleanCoding questionAllowed
cleanTranslation requestAllowed

crawdad

NEEDS ME NOW
Pending
Incidents
WHAT IS HAPPENING
Overview
Activity
Agents
Sessions
CONTAINMENT
Enforcement
Workspace
RULES
Policy
Contextual Agency
Rules
Servers
Threats
EVIDENCE
Audit
Compliance
Fleet
Red Team
SETUP
Connect Agent
Settings
Data Governance
SessionsLocal
RECENT PROTECTION EVENTS
MCP server response injection
L1+pipelineblocked
Pattern: role_switch_you_are_now
How it works: Identity manipulation that attempts to redefine the agent's behavior and persona, causing it to act outside its intended purpose and bypass its safety measures.
Risk: The agent could have adopted a new persona with no safety restrictions, enabling arbitrary harmful actions.
Action: blocked
Create Rule →
Credential leak in output — AWS access keyblocked

crawdad

NEEDS ME NOW
Pending
Incidents
WHAT IS HAPPENING
Overview
Activity
Agents
Sessions
CONTAINMENT
Enforcement
Workspace
RULES
Policy
Contextual Agency
Rules
Servers
Threats
EVIDENCE
Audit
Compliance
Fleet
Red Team
SETUP
Connect Agent
Settings
Data Governance
PolicyLocal
50 rules across 1 policy. This is the KDL enforcement engine — ordered allow / ask / deny / kill, evaluated on every request.
TEST MODE — simulate policy evaluation against a tool call
{ "tool": "Bash", "args": { "command": "cat ~/.aws/credentials" } }
Run Evaluation
CRAWDAD DEFAULTS · BUILT-IN PROTECTIONS
Allow Read**Read operations
Deny Read**/.env **/credentials.json **/.netrcRead operations
Deny Read**/.ssh/id_* **/.aws/credentialsRead operations
Deny Read**/crawdad/policies/**Self-protection
Kill Read/System/** /private/var/db/**Read operations
Allow Write/tmp/**Write protections
Deny Write/etc/** /System/** /Library/**Write protections
Killmkfs dd :(){ :|:& };:Destructive
Killgit push --force origin mainDestructive

Fleet Console

← All Customers
Apex Manufacturing
SCOPES
Apex Manufacturing23
Default1
Engineering8
Production Floor14
Northstar Managed IT / Apex Manufacturing MONITORFLEETTHREATSGOVERNANCECONTROLREPORTAUDITAdministrator
Metadata Only— raw content stays on-device
Demonstration environment. Detections shown are recorded verdicts reported by devices, not enforcement observed live.
TOTAL DETECTIONS
70
TODAY
0
last 24 hours
BLOCK RATE
60%
42 blocked
CRITICAL
14
immediate attention
BY CATEGORY
credential exposure   data exfiltration   policy violation
prompt injection   unauthorized code
BY AGENT
Claude Code   28
Windsurf   14  ·  Cursor   14  ·  Copilot   14

Fleet Console

← All Customers
Apex Manufacturing
SCOPES
Apex Manufacturing23
Default1
Engineering8
Production Floor14
Northstar Managed IT / Apex Manufacturing MONITORFLEETTHREATSGOVERNANCECONTROLREPORTAUDITAdministrator
Telemetry Depth Policy
Controls what telemetry data leaves each device. Changes require dual authorization.
Current depth:Metadata Only
Only detection metadata — category, severity, verdict, agent name — leaves each device. Raw content stays local.
Governance Actions
All changes require a second authorized operator to approve (dual authorization).
Request: Enable Full TelemetryRequest: Lock Policy

crawdad

NEEDS ME NOW
Pending
Incidents
WHAT IS HAPPENING
Overview
Activity
Agents
Sessions
CONTAINMENT
Enforcement
Workspace
RULES
Policy
Contextual Agency
Rules
Servers
Threats
EVIDENCE
Audit
Compliance
Fleet
Red Team
SETUP
Connect Agent
Settings
Data Governance
EnforcementSimple  |  Rich
MONITORING Monitoring — detection on, egress lock off MonitorEgress Off● Fails closed
STRENGTHEN PROTECTION
Turn on enforcement — installs the OS egress lock. Single tap.Turn on enforcement
▶ Reduce protectionCEREMONY-GATEDconsequence dialog + typed confirmation + admin re-auth
ENFORCEMENT AUDIT STREAM
TAMPER-EVIDENT CHAIN   1021 entries  ·  head #1021 Verify chain

Fleet Console

← All Customers
Apex Manufacturing
SCOPES
Apex Manufacturing23
Default1
Engineering8
Production Floor14
Northstar Managed IT / Apex Manufacturing MONITORFLEETTHREATSGOVERNANCECONTROLREPORTAUDITAdministrator
Audit & Forensic ReportCSV ExportPDF Report
Cryptographically verified audit trail — scope-filtered by RBAC grants.
TAMPER EVIDENCE   cryptographic audit chain integrity
NOT YET VERIFIEDVerify Integrity
Chain Head: seq 58 — 5729f5f8820cbfe9645d53e999a9fbeb7025b059f...
Verifying Key (Ed25519): aM3FBSWtHqkqFyi2yr3y4ciBhsJK0YfCBn5fLOGMiR4=
Total Chained: 58
Independent verification: Each entry hash = SHA-256(prev_hash + event_type + event_data + timestamp). Signatures are Ed25519 over (entry_hash, chain_seq). Verify offline with crawdad-verify.

Fleet Console

← All Customers
Apex Manufacturing
SCOPES
Apex Manufacturing23
Default1
Engineering8
Production Floor14
Northstar Managed IT / Apex Manufacturing MONITORFLEETTHREATSGOVERNANCECONTROLREPORTAUDITAdministrator
Effective Policy
Policy provenance for Apex Manufacturing via device apx-station-004 (from child scope) · 23 devices in subtree
PROTECTION MODEReducedSET HERE
Fleet Commands
POLICY
Set Protection ModePush KDL PolicyDeploy Fleet Policy
DEVICE MANAGEMENT
Quarantine
Reversible soft stop. Keeps protection active, isolates the device.
Unenroll
Cleanly leaves the fleet. Reverts to standalone. Re-enrollable.
Decommission
Permanent removal. Serious and difficult to reverse.
Set Protection Mode
Target: Apex Manufacturing and its subtree (23 devices across 4 scopes)
Set Protection Mode — Paused
This will apply to 23 devices across 4 scopes in Apex Manufacturing and its subtree.
← BackConfirm & send
crawdad.

Press play
crawdad.
0:00 / 0:00