The Astragar platform
Aeguard is the endpoint sensor. Behind it, Astragar turns raw cyber findings into quantified business and regulatory risk: the dollar-and-board language you can put in front of the audit committee, not a spreadsheet of CVEs. One platform, three connected layers: DRM, VRM and GRC.

Why now
The gap between attack speed and detection speed is now measured in orders of magnitude. And the newest thing moving inside that gap isn’t malware, it’s the AI agents your own people installed, running with file, tool and network permissions nobody is checking.
When the claim is assessed
82%
trace to incomplete MFA, not a technology failure
Coalition
$2.3M
average coverage gap carried by mid-size businesses
40%
of cyber insurance claims are denied
Advisen Cyber Claims Report
Flagship capability
What it reads · the declared rulebook
Permission rules: allow / deny / ask
MCP tool grants: which external tools it may call
Trusted-folder scopes: the directories it may touch
CLAUDE.md / AGENTS.md: the agent’s own written rulebook
What it returns · a verdict per rule
HONORED: the action stayed within its declared permission
VIOLATION: it did something its own rulebook forbids
UNDECLARED: it acted where no rule exists, a blind spot
UNVERIFIABLE: declared, but not yet observable
From risk score to risk transfer
Insured · Enterprise
Continuous, un-gameable evidence that agents stay contained. Better terms and fewer point-in-time questionnaires.
Insurer
ARP as an underwriting and pricing input. Monitor policy warranties in real time. Evidence-based cyber and AI-liability cover.
Reinsurer
Aggregate ARP across portfolios to model the systemic accumulation risk of AI-agent adoption, a new, correlated risk class.
150
conversations with carriers, brokers and enterprises coming out of the Global Insurance Accelerator.

The AI-agent risk score
The Agent Risk Profile places every agent by attack surface times blast radius, net of the controls actually in place: Exposed, Hardened, Limited or Contained. Continuous, tamper-evident and framework-mapped, so it holds up when someone asks how you got the number.
Continuous
Tamper-evident
Framework-mapped
Enterprise edition · in development
Without changing the security model.
• Single pane of glass across every enrolled endpoint
• Fleet-wide AI-agent and rulebook-compliance rollup
• Central policy distribution: rules, scopes, vuln policy
• Cross-device forensic search in one investigation
• Org-level posture and compliance reporting, with audit export
• Tamper-evidence at scale: aggregated hash-chain checkpoints
• Enterprise controls: RBAC, SSO / SAML, native GRC and SIEM feeds
NOW: Beta on macOS and Windows, Apple Endpoint Security entitlement granted
NEXT: Fleet console, design-partner development
THEN: General availability
Who it’s for
Security & IT leadership
See and govern the AI agents already running on your estate, and prove it. CISO, IT director, or your vCISO.
Risk & finance
A defensible, continuous AI-agent risk score instead of an annual questionnaire, and evidence that holds up at claim time.
Compliance / DPO
Compliance-grade FIM and an audit trail that can’t be quietly edited. Evidence on demand.
Underwriter / Insurer
Un-gameable evidence as a pricing and warranty-monitoring input.
Broker
Tell similar risks apart. Advise on live risk, not forms.
Board
A straight answer to “what are our AI agents actually doing?”












