Agentic Detection & Response

AIDR is the runtime security foundation for All Agents
on Every Endpoint

Start with runtime visibility and detection, investigate through session-level evidence, then expand into identity, data, execution, and remediation controls as each response capability is validated.

AIDR / LIVE TRACE_01
Live session evidence
session:sess-7f3a / turn:018 / trace:verified
14:32:07HIGHtool_call / ReadFile -> sample/policy.yaml
tenant: sample-org / project: demo-project / session: sess-7f3a
Events: 2,847Alerts: 3Connected
Why AIDR

Traditional security tools can't understand Agents

Enterprises are running more Agents on endpoints, but security teams can't see their actual behavior chains.

Evidence hierarchy / verified trace

session:sess-7f3a

└─ turn:018 / identity:developer

└─ step:041 / ReadFile / policy:recorded

01

Traditional EDR tracks what processes do

AIDR reconstructs what Agents did and what they affected

02

Process → File → Network 5-tuple

Session → Identity → Toolchain → Model → Semantic Trace

03

Signature-based detection

Runtime detection + Investigation evidence + Response controls

How It Works

From Visibility to a Response Loop

01 / Observe

Runtime Visibility

DeepTracing real-time tracking of tool calls, model loads, file access, network activity, MCP communications, and permission decisions — every alert traces back to session-level context.

02 / Detect & Investigate

Detection & Investigation

AI-BOM, behavioral baselines, and drift rules locate anomalies; session evidence then shows which identities, data, and execution paths were affected.

03 / Respond

Phased Response

Audit is available today. Warn, Approve, and execution blocking are delivered in stages and shown with explicit availability states.

AIDR / dual-path runtime architecture

Evidence path

Available

01Collect
02Normalize
03Session evidence
04Detect & investigate

Response path

Phased delivery

01Audit · available
02Warn · coming
03Approve · coming
04Block · roadmap
Core Advantages

Six Differentiating Capabilities

Full Endpoint Agent Observability

Unified collection of six event types, supporting IDE Agent, CLI Agent, MCP-driven, and custom Runtimes.

DeepTracing Evidence Chain

Every alert traces back to session-level Trace, not just process or network 5-tuple.

AI-BOM Asset Graph

Model, toolchain, MCP, and Agent dependency graph with diff support and compliance inventory.

Detection & Investigation Loop

Use baselines to locate drift, then return to session evidence to confirm identity, data, and execution impact.

Transparent Response Roadmap

Audit is available; Warn, Approve, SoftBlock, and HardBlock are delivered only after validation.

Three Deployment Models

Full SaaS, hybrid, and private models define different data boundaries; hybrid and private keep raw events customer-side.

Coverage

Cover Every Integratable Agent Runtime

Beyond MCP: cover IDE, CLI, MCP, and custom Agents, while labeling each runtime by its actual observability depth.

IDE Agent

Cursor / Copilot

CLI Agent

Terminal Automation Agent

MCP Agent

Cross-tool Orchestration Agent

Custom Agent

Enterprise Custom Runtime

Level AFully Managed

SDK/Sidecar integration, outputs six core events, supports policy feedback

Level BPartially Managed

Process/session identifiable, partial semantic events

Level CShadow Agent

Only system calls visible, added to onboarding backlog

Deployment & Compliance

Data Sovereignty, Boundaries Defined by Mode

Hybrid and private deployments keep raw events customer-side by default. Full SaaS stores and processes them inside the customer's selected cloud tenant boundary.

Data TypeStorage LocationOutboundNotes
Raw Event DetailsDeployment-dependentBy modeCloud tenant for SaaS; customer-side for hybrid/private
Masked Event SummarySaaS + CustomerYesHashed paths/domains
Alert MetadataSaaS + CustomerYesNo plaintext sensitive fields
AI-BOM Asset ListSaaS + CustomerConfigurableSupports stats-only sync
Policy ConfigSaaS → CustomerYesRequires signature verification
Integration Evidence

Measured by integration, not vanity metrics

11

Agent runtime integrations in the current matrix

OTel

OpenTelemetry-aligned telemetry

3

SaaS / hybrid / private deployment models

AIDR / next evidence record

Start Securing Your Agents

Start with endpoint runtime visibility and detection, then build an Agent security foundation that is investigable, auditable, and ready for phased response.