Skip to content

Security agents that stay inside the perimeter.

Run triage and response where the evidence is: on the hosts, next to the logs, inside your network. Agents use only the tools you allow, risky actions wait for a person, and every step stays in the job’s history.

Live outputCompleted

$ oz0 run alert-triage '{"alert": "EDR-88213", "host": "fin-ws-042"}'

alert-triage → edr.alert {"id":"EDR-88213"}

alert-triage ← edr.alert powershell.exe started by winword.exe on fin-ws-042

alert-triage → host.process_tree {"pid":7312}

alert-triage ← host.process_tree winword.exe > powershell.exe -enc > rundll32.exe

alert-triage ⇢ evidence-collector (job edr-88213/evidence-collector-1)

evidence-collector: Collected 14 artefacts, SHA-256 manifest attached.

alert-triage: Likely a malicious macro. Isolation of fin-ws-042 is waiting for your approval.

JobCost
alert-triage$0.06
evidence-collector$0.01
Example output. The tools come from plugins: your own MCP servers or existing packages.

Why it belongs on your own machines.

Evidence should not travel
Logs, process trees and disk artefacts stay on the machines that hold them. The agent runs there, and only its findings leave the host.
Nothing drastic without a yes
Isolating a host or disabling an account is a tool that needs approval. The job waits as long as it takes and records who said yes.
Every step on record
Each model call and tool call is a step in the job’s history, with its input and its result, so an investigation can be followed and audited afterwards.

Agents teams build.

Each one is a plugin: an agent definition, the tools it may use and the limits it runs under. Install it from Git and every node that should run it gets it.

  • alert-triageEnriches an alert with process trees, logins and connections from the host that raised it, and rates it.Runs on The host in the alertKept in line by Read-only tools
  • evidence-collectorCollects logs and artefacts on the affected machines and hashes them before anything moves.Runs on Affected hostsKept in line by Allowed paths only
  • containmentIsolates a host or disables an account, and undoes it when the case closes.Runs on The host in the caseKept in line by Approval required
  • vuln-reviewChecks which scanner findings are actually reachable on each machine and drafts the fix list.Runs on Every nodeKept in line by Budget per job

From alert to contained host

Your SIEM or EDR starts the job. The agent does the legwork on the host, and a person makes the call.

  1. Alert

    The SIEM starts a job through the runtime API with the alert ID. A retry with the same job ID follows the same job.

    Runtime API

  2. Triage on the host

    The job lands on the node on the affected machine and gathers what the alert needs.

    The host in the alert

  3. Ask before acting

    The isolate tool needs approval. The analyst sees the evidence and the agent’s reasoning, and decides.

    Web UI

  4. Close with a record

    The job ends with a report, the history of every call and the cost of the investigation.

    The job’s history

What makes it work.

  • mTLS everywhere

    Every node has its own certificate, renewed every 24 hours. A blocked node is refused on its very next call.

  • Secrets stay sealed

    Keys are decrypted only at the edge and on the node that needs them, never in management.

  • Approvals on risky tools

    Mark a tool as needing approval and every call to it waits for a person.

  • A tenant per customer

    Managed providers keep each customer’s nodes, plugins, secrets and history apart.

Where it is going

Hosts that defend each other.

Today agents triage on the host that raised the alert. Next, the nodes on a segment watch out for each other: when one host turns hostile, its neighbours refuse it within seconds, even when the SOC cannot be reached.

Finance segment
SOC
fin-ws-011
fin-ws-018
fin-db-02
fin-ws-042
fin-ws-027
fin-app-01
The line to the SOC is cut. The other hosts recognise the one that turned, refuse it and keep the evidence.
Containment that survives a cut line
Attackers often go for the link to the SOC first. The nodes on a segment keep their policies, act on them locally and hand over the evidence when the line returns.
An identity you can take away
Every node proves who it is on every call, with a certificate only it holds. Revoke a compromised machine once and every peer refuses it. Each investigation gets credentials that expire with it.
Every endpoint, one fleet
A node on every laptop, server and VM in the company is still one system: one registry, one set of policies, rolled out in waves and built to scale with the fleet.

Built for

  • Security operations centres
  • Managed security providers
  • Incident response teams
  • Finance, health and the public sector