Execution graph
ES and NE events become semantic verbs (readFile, spawnProcess, networkConnectExternal) in the behavioral correlation graph. Engine detail: Behavioral detection (appendix). Live UI: Observatory.
Documentation
How the AI agent firewall works — execution graph, enforcement planes, agent classification.
Read scenarios first
ES and NE events become semantic verbs (readFile, spawnProcess, networkConnectExternal) in the behavioral correlation graph. Engine detail: Behavioral detection (appendix). Live UI: Observatory.
Example multi-step rule: secret read → external connect — lab
Two enforcement planes
Optional mf exec
posix_spawn without capability tokens. Default enforcement uses ExecGovernor + policy. Tokens are a fast-path when present.TURI is not EDR, SAST, or prompt filtering — see the comparison on the docs overview.
Running AI agents on Mac at scale? We'll tune policy with you.
Design partners →