NewA botnet shipped no malware at all — the payload was 39 lines of English
Evren

Platform

One decision point, where the action actually happens.

Your identity provider decides who an agent is. Your secrets manager decides what it can hold. Evren decides what it can do on the machine — and proves what it did.

01 · Decide

Execution boundary

Every privileged action is evaluated against a compiled, signed policy before anything runs. A permit is a decision, not a door held open for the rest of the session.

  • Per-call decisions, not per-session grants
  • First-match policy, compiled and MAC-verified
  • Denials are inline — the agent keeps working

02 · Confine

Process isolation

What the daemon permits runs inside a sandbox armed before exec. If the confinement a rule names cannot be applied on that host, the command does not run at all.

  • seccomp default-deny syscall allowlist
  • Landlock filesystem confinement — listed paths only
  • Fail-closed: the filter arms, or the command aborts

03 · Attribute

Agent identity

Policy matches on which agent is asking, not which user account it happens to run under. Five agents on one service account are five identities, not one.

  • SPIFFE attestation as a first-class policy predicate
  • Process-ancestry floor — a child never exceeds its parent
  • Works with the identity your IdP already issues

04 · Prove

Signed audit

One record per decision — permits as well as denials — signed and hash-chained, on its way off the box before anything spawns.

  • ed25519-signed, hash-chained, verifiable offline
  • Streamed off-host over mTLS to a WORM sink
  • Tamper-evident under host root: detection and bounded loss

Where it matters first

Most teams did not procure these. They arrived with an approved tool and a developer’s laptop.

Coding agents

Claude Code, Copilot and anything else with a terminal. They install packages, restart services and spawn shells — because that is the job you gave them.

CI/CD runners

Build agents hold standing privilege on shared hosts and run whatever the pipeline hands them. One compromised dependency reaches everything on the runner.

SRE automation

Runbook agents act on production at machine speed, at hours when nobody is reviewing. The remediation and the outage look identical until afterwards.

Vendor agents

Third-party agents arrive with an approved SaaS integration. You did not write them, cannot inspect them, and did not scope what they touch.

Start with thirty days of visibility

The first thing we deploy denies nothing. You see what your agents actually do, then decide what to change.

Request a demo