Endpoint security for the AI-agent era

The AI agents are already inside your business. Can you prove what they did?

Aeguard is a tamper-evident, on-device sensor that governs the AI agents now running on your machines. It proves, per agent and per machine, that each one stayed inside the rules it declared. Evidence your board, your auditor and your insurer can all rely on.

AI-agent governance

Vulnerability scanning

Behavioural baselining

In beta on macOS and Windows · Apple Endpoint Security entitlement granted

Endpoint security for the AI-agent era

The AI agents are already inside your business. Can you prove what they did?

Aeguard is a tamper-evident, on-device sensor that governs the AI agents now running on your machines. It proves, per agent and per machine, that each one stayed inside the rules it declared. Evidence your board, your auditor and your insurer can all rely on.

AI-agent governance

Vulnerability scanning

Behavioural baselining

In beta on macOS and Windows · Apple Endpoint Security entitlement granted

Endpoint security for the AI-agent era

The AI agents are already inside your business. Can you prove what they did?

Aeguard is a tamper-evident, on-device sensor that governs the AI agents now running on your machines. It proves, per agent and per machine, that each one stayed inside the rules it declared. Evidence your board, your auditor and your insurer can all rely on.

AI-agent governance

Vulnerability scanning

Behavioural baselining

In beta on macOS and Windows · Apple Endpoint Security entitlement granted

The Astragar platform

Quantify and reduce breach risk. Improve regulatory compliance. Protect reputation.

Quantify and reduce breach risk. Improve regulatory compliance. Protect reputation.

Aeguard is the endpoint sensor. Behind it, Astragar turns raw cyber findings into quantified business and regulatory risk: the dollar-and-board language you can put in front of the audit committee, not a spreadsheet of CVEs. One platform, three connected layers: DRM, VRM and GRC.

Why now

Defenders take 241 days. Attackers need 29 minutes.

Defenders take 241 days. Attackers need 29 minutes.

The gap between attack speed and detection speed is now measured in orders of magnitude. And the newest thing moving inside that gap isn’t malware, it’s the AI agents your own people installed, running with file, tool and network permissions nobody is checking.

241 days

To identify and contain a breach: 158 to identify, 83 to contain. IBM Cost of a Data Breach 2025

241 days

To identify and contain a breach: 158 to identify, 83 to contain. IBM Cost of a Data Breach 2025

29 minutes

What attackers now need to move from access to impact. Industry reporting, 2025

29 minutes

What attackers now need to move from access to impact. Industry reporting, 2025

$3.31M

Average total cost of a breach for organisations under 500 employees. IBM 2025

$3.31M

Average total cost of a breach for organisations under 500 employees. IBM 2025

70.5%

Of attacks target mid-size businesses, not large enterprises. Verizon DBIR 2024

70.5%

Of attacks target mid-size businesses, not large enterprises. Verizon DBIR 2024

The blind spot

Your EDR sees processes. It doesn’t see agents.

Your EDR sees processes. It doesn’t see agents.

An AI agent is not a malware signature. It is a legitimate, signed binary doing legitimate things, until the moment it does something its own rulebook forbids. Classic endpoint tooling has no concept of a declared agent permission, so it cannot tell the difference.

Shadow AI

Agents installed without approval, running with broad file and network scope. Nobody has an inventory.

Silent re-scoping

Permissions and trusted folders widen over time. The change is never reviewed.

No attributable record

When something moves, you can’t prove which agent did it, on which machine, or when.

When the claim is assessed

40% of cyber claims are denied. 82% because a control couldn’t be proven.

40% of cyber claims are denied. 82% because a control couldn’t be proven.

82%

trace to incomplete MFA, not a technology failure

Coalition

$2.3M

average coverage gap carried by mid-size businesses

40%

of cyber insurance claims are denied

Advisen Cyber Claims Report

Most denied claims aren’t denied because the defence failed. They’re denied because nobody could evidence that the control was in place at the moment it mattered. Self-reported questionnaires and point-in-time screenshots don’t survive a claims assessment.

Most denied claims aren’t denied because the defence failed. They’re denied because nobody could evidence that the control was in place at the moment it mattered. Self-reported questionnaires and point-in-time screenshots don’t survive a claims assessment.

Aeguard produces the opposite: an append-only, hash-chained record on the machine itself, which cannot be quietly edited after the fact. The same evidence that tells your CISO what the agents did tells your insurer that the control held.

Aeguard produces the opposite: an append-only, hash-chained record on the machine itself, which cannot be quietly edited after the fact. The same evidence that tells your CISO what the agents did tells your insurer that the control held.

The record you’ll wish you had on the day of the claim.

The record you’ll wish you had on the day of the claim.

Flagship capability

Every AI agent declares what it’s allowed to do. Aeguard proves it stayed inside those rules.

Every AI agent declares what it’s allowed to do. Aeguard proves it stayed inside those rules.

What it reads · the declared rulebook

Permission rules: allow / deny / ask
MCP tool grants: which external tools it may call
Trusted-folder scopes: the directories it may touch
CLAUDE.md / AGENTS.md: the agent’s own written rulebook

What it returns · a verdict per rule

HONORED: the action stayed within its declared permission
VIOLATION: it did something its own rulebook forbids
UNDECLARED: it acted where no rule exists, a blind spot
UNVERIFIABLE: declared, but not yet observable

Turns AI policy from a promise into evidence: attributed to the exact agent, per machine, over time. Catches misconfiguration and silent re-scoping.

Turns AI policy from a promise into evidence: attributed to the exact agent, per machine, over time. Catches misconfiguration and silent re-scoping.

Two scans

Seeing the exposures EDR is blind to.

Seeing the exposures EDR is blind to.

Unified vulnerability scan

One scan, two attack surfaces: classic hygiene and the AI-specific exposures other scanners miss.

• Machine hardening: FileVault, firewall, OS posture
• AI-agent attack surface: exposed local inference, permissive rulebooks, secrets in agent-trusted folders

Severity-ranked, and every scan is chained into the tamper-evident log.

Behavioural baselining

Learns each machine’s normal, then judges every new event against it, not against a generic threshold.

• Per-machine baseline: weekday × hour cadence, processes, network, USB
• Matures automatically: about a week and 250+ observations, then it stops flagging what’s normal for that machine

The complete on-device sensor

Everything else, working underneath.

Everything else, working underneath.

AI-agent detection & attribution

Signature, behavioural, MCP inventory and process-lineage. Attributes shadow-AI file, network and process activity back to the agent that caused it.

Agent Risk Profile (ARP)

Attack surface, blast radius and controls per agent, mapped to OWASP LLM Top-10 and MITRE ATLAS. Defensible risk, not a black box.

Tamper-evident forensic log

Append-only events in a BLAKE3 hash-chain, chain-head mirrored to the Keychain. Any edit, deletion or database swap is detectable.

Real-time endpoint monitoring

Kernel-level exec, file, code-injection and persistence events, each carrying the actor PID. Apple Endpoint Security on macOS. Detect-only, no blocking.

File integrity monitoring

Baseline plus streamed BLAKE3 over scoped folders with custom exclusions. Compliance-grade FIM for PCI-DSS, ISO 27001 and SOC 2.

Local-first & private by design

On-device, SQLCipher-encrypted, no keystroke capture, no cloud dependency. Runs on air-gapped and regulated endpoints.

Detects what EDR misses · Trust the record, the log can’t be quietly edited · Your data never leaves the machine.

Private by design

Nothing leaves the machine.

Nothing leaves the machine.

Aeguard is local-first by architecture, not by configuration. The database is SQLCipher-encrypted on the endpoint. There is no keystroke capture and no cloud dependency, so it runs unchanged on air-gapped and regulated machines. You get the forensic record without creating a new central store of employee activity to defend, or to explain to your works council.

On-device

SQLCipher-encrypted

Air-gap capable

From risk score to risk transfer

A score the enterprise, its insurer and its reinsurer can all trust.

A score the enterprise, its insurer and its reinsurer can all trust.

Insured · Enterprise
Continuous, un-gameable evidence that agents stay contained. Better terms and fewer point-in-time questionnaires.

Insurer
ARP as an underwriting and pricing input. Monitor policy warranties in real time. Evidence-based cyber and AI-liability cover.

Reinsurer
Aggregate ARP across portfolios to model the systemic accumulation risk of AI-agent adoption, a new, correlated risk class.

150

conversations with carriers, brokers and enterprises coming out of the Global Insurance Accelerator.

The AI-agent risk score

One score for how contained your agents actually are.

One score for how contained your agents actually are.

The Agent Risk Profile places every agent by attack surface times blast radius, net of the controls actually in place: Exposed, Hardened, Limited or Contained. Continuous, tamper-evident and framework-mapped, so it holds up when someone asks how you got the number.

Continuous

Tamper-evident

Framework-mapped

Enterprise edition · in development

Everything on the endpoint, centralized across your estate.

Everything on the endpoint, centralized across your estate.

Without changing the security model.

• Single pane of glass across every enrolled endpoint
• Fleet-wide AI-agent and rulebook-compliance rollup
• Central policy distribution: rules, scopes, vuln policy
• Cross-device forensic search in one investigation

• Org-level posture and compliance reporting, with audit export
• Tamper-evidence at scale: aggregated hash-chain checkpoints
• Enterprise controls: RBAC, SSO / SAML, native GRC and SIEM feeds

NOW: Beta on macOS and Windows, Apple Endpoint Security entitlement granted

NEXT: Fleet console, design-partner development

THEN: General availability

Who it’s for

Built for whoever has to answer the question.

Built for whoever has to answer the question.

Security & IT leadership

See and govern the AI agents already running on your estate, and prove it. CISO, IT director, or your vCISO.

Risk & finance

A defensible, continuous AI-agent risk score instead of an annual questionnaire, and evidence that holds up at claim time.

Compliance / DPO

Compliance-grade FIM and an audit trail that can’t be quietly edited. Evidence on demand.

Underwriter / Insurer

Un-gameable evidence as a pricing and warranty-monitoring input.

Broker

Tell similar risks apart. Advise on live risk, not forms.

Board

A straight answer to “what are our AI agents actually doing?”

FAQs
FAQs

Answers to your questions

What does Astragar do?

What does Astragar do?

What does Astragar offer?

What does Astragar offer?

What does Astragar offer?

Are vulnerability details shared with carriers or brokers?

Are vulnerability details shared with carriers or brokers?

Is Astragar a licensed insurance broker or agent?

Is Astragar a licensed insurance broker or agent?

Does Astragar replace vulnerability scanners?

Does Astragar replace vulnerability scanners?

Does Astragar replace vulnerability scanners?

How is Astragar different from point security or compliance tools?

How is Astragar different from point security or compliance tools?

How is Astragar different from point security or compliance tools?

Can Astragar support third-party and vendor risk visibility?

Can Astragar support third-party and vendor risk visibility?

Can Astragar support third-party and vendor risk visibility?

Which compliance frameworks does Astragar support?

Which compliance frameworks does Astragar support?

Which compliance frameworks does Astragar support?

How can I get started?

How can I get started?

Get started
Get started

Prove what your AI agents did.

Aeguard is in beta on macOS and Windows. We’re onboarding design partners now.

Get started

Prove what your AI agents did.

Aeguard is in beta on macOS and Windows. We’re onboarding design partners now.

©Astragar All rights reserved.

©Astragar All rights reserved.

©Astragar All rights reserved.