Govern every AI Agent your enterprise depends on.

Built with design partners

Building with design partners across banking, healthcare, and public-sector teams in APAC.

The Problem

Old software waits. AI agents act.

Agents call tools, read customer data, and trigger payments on their own — but the controls your enterprise relies on were built for software that waits. So when an agent heads for production, three questions block approval.

Is it safe?

The CISO’s question — who owns the agent, why its access keeps growing, and which shadow agents nobody registered.

Is it compliant?

The compliance question — the proof a regulator wants, scattered across a dozen tools and inboxes.

Is it worth it?

The CFO’s question — no way to tie spend to a specific agent, team, or business outcome.

The thing standing between a promising pilot and a production system is not smarter AI. It is governance.

Products

Two products. One agent governance mission.

AgentGuardian Open Source · Apache-2.0

AgentGuardian Open Source.

Open-source red teaming for AI agents.

For developers, security engineers, and AI builders who want to test agents locally or in CI/CD.

  • Prompt injection testing
  • Tool abuse testing
  • RAG poisoning testing
  • Memory attack testing
  • AIVSS scoring
  • Local reports
  • SARIF / JSON / HTML exports
  • CI/CD gate
$ pip install agent-guardian
$ agent-guardian scan ./my_agent.py
$ agent-guardian serve
AgentGuardian Enterprise · SaaS

AgentGuardian Enterprise.

Enterprise AI agent governance platform.

For security, risk, compliance, and AI platform teams governing agents across the organization.

  • Agent discovery
  • Agent registry & shadow-agent inventory
  • Lifecycle approvals · Agent Contracts
  • Scheduled & continuous scans
  • Runtime policy enforcement
  • Continuous monitoring
  • Drift detection & re-approval
  • Per-agent cost tracking (early access)
  • Signed evidence packs
  • SSO · RBAC · audit logs
  • Customer-resident deployment
Enterprise Platform

What AgentGuardian Enterprise does.

Govern

Make every agent accountable before it runs — an owner, a purpose, a risk tier, an approval, and a review-or-retire date. No more anonymous agents.

Secure

Run continuous adversarial red teaming against prompt injection, tool abuse, RAG poisoning, memory attacks, supply-chain risk, and agent-to-agent compromise — and block risky releases before they ship.

Measure

Tie every token and every dollar to a specific agent, team, and budget — per-agent cost metering, budget alerts, and departmental showback. Early access.

Enforce

Turn governance into real control — least-privilege access validated against each contract, unsafe actions denied by your cloud's own controls, and per-agent and fleet-wide kill switches that cut access in seconds. Nothing sits in the request path.

Prove

Generate signed evidence packs with attack traces, AIVSS scores, findings, remediation guidance, and governance mapping.

How It Works

How AgentGuardian works.

01 · Govern
Discover and register

Find every agent in your estate — including the ones nobody registered — and give each an owner, a purpose, and a risk tier.

02 · Govern
Approve with a contract

Risk-tiered approval produces a signed Agent Contract that spells out exactly what the agent is allowed to do.

03 · Secure
Attack before attackers do

Run adversarial probes against prompt, tools, RAG, memory, and multi-agent behavior — AIVSS-scored, with unsafe releases blocked.

04 · Enforce
Enforce in your cloud

Least-privilege access validated against the contract, deny rules in your cloud's own controls, and a kill switch that revokes in seconds.

05 · Prove & Measure
Prove it, and price it

Signed evidence packs for audit and governance review — and every token and dollar tied to a specific agent and budget.

Deployment

Runs inside your cloud account.

The data plane installs into your own AWS account. We operate the control plane — orchestration and policy, never your data.

Your AWS account.

The data plane. Everything sensitive is generated, processed, and stored inside your walls.

Data plane · customer-resident
  • Prompts & tool calls
  • Agent telemetry & logs
  • Evidence packs
  • Signing keys · your KMS

Our control plane.

Scan orchestration, policy authoring, and dashboards — metadata only, never payloads.

Control plane only
  • Scan orchestration
  • Policy authoring
  • Posture dashboards
  • No prompts · no keys

Your prompts, telemetry, and keys never leave your walls — the design choice that lets a regulated bank say yes.

AWS today — discovery for Google Vertex AI and Azure OpenAI is next on the roadmap.

Evidence & Trust

Audit-ready evidence from real adversarial tests.

AgentGuardian does not rely only on questionnaires or posture inference. Every assessment can produce a signed evidence pack with attack traces, scores, findings, and framework mapping.

  • Agents in scope
  • Attack transcript
  • AIVSS score
  • Findings by severity
  • Policy decisions
  • Remediation guidance
  • Framework mapping
  • Verification manifest
AgentGuardian · Evidence Pack✓ Signed
EP-2026-Q1-0007
Issued: 2026-05-12 · Issuer: AgentGuardian · Customer-resident KMS
Agents in scope
147 · 9 high-risk
Framework mapping
EU AI Act · NIST AI RMF · ISO 42001
OWASP scorecard
92 / 100
Approvals logged
412
sha256: 4f8a92e1c0b3d7a9e2f4c1b8d6a0e3f7c9b2a1e8d4c7f0b3a6e9d2c5f8b1a4e7
Regional regulator coverage
MAS SingaporeAPRA AustraliaDORA European UnionSR 11-7 US Federal ReserveRBI India · roadmapOJK Indonesia · roadmapBNM Malaysia · roadmapBSP Philippines · roadmap

These are not optional and the clocks are running — MAS’s guidelines carry a 12-month transition, APRA CPS 230 is already in force, and the EU AI Act’s high-risk obligations bind in 2026.

Request sample evidence pack
MAS SAFR alignment · Singapore FSI

SAFR-native runtime governance for every AI agent action.

On 3 July 2026 the Monetary Authority of Singapore published Safeguards for Agentic Finance at Runtime (SAFR) — the industry framework MAS expects every FSI enterprise in Singapore to implement for governing AI agents at runtime. AgentGuardian was built to SAFR's exact pattern before SAFR existed: policy-bound execution, real-time validation, tamper-evident audit, and interoperability.

SAFR runtime element (MAS, July 2026)AgentGuardian component
Agent IdentityAgent Registry · workload identity · mandate binding
Controls RepositoryPolicies · Testing scenarios · versioned control bundles
Disposition Engine6-gate policy chain · Identity → RBAC → DLP → PII → Budget → Human approval
Governance EnvelopeRequest context + action trace + policy digest per invocation
Audit Log (tamper-evident)Signed evidence pack · hash-chained ledger · replayable forensics
Dispositions · Deny / Escalate / Auto-Execute / ObserveGate outcomes: block · human approval · approve · monitor
Controls · Authorization · Exposure · Rate · Evidence QualityAuthority boundary · budget guardrails · rate limits · risk classification
Deployment · Native + GatewayIn-tenant collector (native) + control-plane API (gateway)
SAFR is necessary but not sufficient.

MAS's own guidance calls out gaps SAFR does not close — prompt injection, memory poisoning, tool supply-chain trust, multi-agent collusion. AgentGuardian carries those risks as first-class controls in the same runtime plane, so a single deployment satisfies the SAFR baseline and the broader agent security perimeter.

Request SAFR alignment briefRead the MAS SAFR paper
Built For

Built for the teams accountable for AI agents.

Security teams

Find and test the real AI agent attack surface.

Continuous adversarial red teaming against prompt injection, tool abuse, RAG poisoning, memory attacks, and agent-to-agent compromise — across every agent in your estate.

Risk & governance teams

Turn AI governance into signed, reviewable evidence.

Every assessment produces a signed evidence pack with attack traces, AIVSS scores, findings, remediation guidance, and framework mapping for audit and regulator review.

AI platform teams

Give developers open-source red teaming, keep production governed.

Developers run AgentGuardian Open Source locally and in CI/CD. The same engine powers AgentGuardian Enterprise — so what developers see in build is what the security team sees in production.

Finance & FinOps teams

Prove which agents earn their keep.

Per-agent cost metering ties every token and every dollar to a specific agent, team, and budget — with budget alerts and departmental showback for finance review. Early access.

FAQ

Frequently asked questions.

Is AgentGuardian Open Source the full platform?
No. AgentGuardian Open Source is the red-teaming toolkit. AgentGuardian Enterprise adds discovery, runtime enforcement, monitoring, audit workflows, SSO, RBAC, customer-resident deployment, and signed evidence packs.
Is AgentGuardian a guardrail?
AgentGuardian Open Source is not a runtime guardrail. It is a red-teaming toolkit. AgentGuardian Enterprise enforces without sitting in your agents' request path: it validates least-privilege access against each agent's approved contract, monitors runtime signals for cost, action, and security alerts, and provides an auditable per-agent and fleet-wide kill switch that revokes access in seconds. Deny rules compile into your cloud provider's native controls — AWS enforces them, so nothing new sits in the request path and no latency is added.
Does our data leave our environment?
AgentGuardian Enterprise is designed with a customer-resident data plane so regulated telemetry, prompts, tool calls, logs, evidence, and keys stay inside your environment.

Start with red teaming.
Scale to enterprise governance.

Run AgentGuardian Open Source locally in minutes, or book a demo to see the enterprise governance platform.

Try Open Source