Product Overview
Three Layers, Transparent Progress Toward Response
Runtime visibility provides the foundation, detection and evidence support investigation, and response controls ship in validated stages.
Observe
Observe & DeepTracing
Unified collection of six core events: tool_call, permission, model_load, file_access, network_activity, mcp_activity. Each event carries traceId/sessionId for full behavior chain traceability.
Learn More- Session-level Trace Tracking
- Six Semantic Event Types
- SDK/Sidecar/Proxy Multi-mode Integration
- Client-side Masking Before Upload
Detect & Investigate
Detect, Investigate & AI-BOM
AI-BOM, baselines, and drift rules locate anomalies; session traces then investigate affected identities, data, tools, and connections.
Learn More- AI-BOM Asset Graph & Version Diff
- Baselines & Drift Rules D01-D06
- Session-Level Investigation Evidence
- OWASP Risk Mapping
Respond
Respond & Govern
Audit is available today. Warn, Approve, SoftBlock, and HardBlock remain staged capabilities until each host protocol passes compatibility and rollback gates.
Available: AuditComing Soon: Warn, ApproveRoadmap: SoftBlock, HardBlock
Learn More - Audit Available
- Warn / Approve Coming Soon
- SoftBlock / HardBlock Roadmap
- SIEM/SOAR Response Integration
Architecture Overview
Client-side semantic collection + command center detection orchestration, two-layer architecture for decoupled delivery.
Client-Side Runtime
Agent Runtime
DeepTracing Collector
Context Enricher
Secure Spooler
Local Detector
Encrypted Upload
AIDR Command Center
Ingestion API
Detection Engine
AI-BOM Engine
Baseline & Drift
Alert Orchestrator
Console UI