DenovosecurityBuilding Trust from Scratch
Platformchevron_rightAI Safety

Three pillars for securing autonomous agents.

Denovo secures AI agents and the MCP servers they reach at the moment they act. Together the pillars take a security team from reading logs after the fact to stopping an action while it is still a request.

Where the module applies
memoryAgent platformsChatGPT Work, Claude Code, Cursor and in-house agents.
extensionMCP serversThe tools an agent can reach, internal and third party.
databaseAgent memoryRAG vector stores and the context an agent assembles.
dnsWorkloads and jobsServices and scheduled tasks that call models on their own.
Platformchevron_rightAI Safety · Agent Observability

Full visibility into every agent and tool.

Agents spawn sub-agents, call tools and rewrite their own memory between one prompt and the next. Denovo follows that execution as it happens, across your network, your APIs and the endpoints agents run on.

inventory_2Agent and tool inventoryContinuously discovers the AI agents in use, from ChatGPT Work, Claude Code and Cursor to custom LangChain and CrewAI scripts, together with the external MCP servers they reach.
account_treeIntent and context tracingFollows the lineage of an agent's sub-goals: memory reads and writes in RAG vector databases, system prompts and every tool invocation, as they happen.
streamTelemetry and session analyticsCaptures API payload metadata, system call executions, token usage and cross-agent communication on one stream.
trending_upBehavioral driftCompares an agent's activity with how it normally behaves, so anomalies and execution drift surface early.
hubMulti-agent topologyShows which agents call which, and which tools sit behind them, including sub-agents started mid-task.
receipt_longSession evidenceKeeps each session as a reviewable record of what the agent read, called and sent.
Agent sessionSample session, traced in real time
Tracing
memoryAgentCoding assistant
account_treeSub-agents2 started mid-task
handymanTools calledrepo.read, crm.lookup
databaseMemoryVector store read and write
trending_upDriftNew tool first seen today
notificationsFlagged for review
routeIn the path
memoryAgents and sub-agentsCall models, tools and memory
radarAgent ObservabilityExecution graphs, tracing and telemetry
shield_personSecurity teamSees behavior as it happens
Platformchevron_rightAI Safety · Agentic Data Security

Sensitive data stays inside the boundary you set.

Protection has to be dynamic and intent-aware, because an agent gathers its own context: it reads documents, queries vector stores and passes the results into prompts, tool parameters and downstream calls.

visibility_offInline redaction and maskingSanitizes PII, PHI, financial data and proprietary code from prompts, context windows and tool parameters before they reach an external model.
databaseContext and memory sanitizationScans long-term agent memory for context poisoning, exfiltration pathways and persistent prompt injection payloads.
blockData loss prevention for agent outputStops agents from sending secrets, API keys and proprietary data through untrusted tools, webhooks or external channels.
fact_checkContent-aware classificationClassifies data by what it contains, with no per-application rule tuning.
arrow_outwardDestination-aware policyBinds a rule to where the data is going, not only to what it is.
descriptionYour own documentsRecognizes fragments of indexed internal files when they appear in a prompt or a tool call.
Context inspectionSample tool call, inspected in path
Enforcing
inputChannelTool argument
manage_searchFoundCustomer email, contract value
databaseMemory sourceIndexed contract store
arrow_outwardDestinationExternal model
visibility_offActionRedact before sending
task_altAllowed with redaction
routeIn the path
descriptionPrompts, memory and tool callsCarry data out of your estate
data_loss_preventionAgentic Data SecurityClassifies, redacts and sanitizes in path
neurologyModels and destinationsReceive only permitted data
Platformchevron_rightAI Safety · Agent Action Control

A deterministic gate in front of every consequential action.

Observability tells you what an agent did. Action control decides what it may do. The gate sits inside the execution loop and returns a verdict before the action reaches your infrastructure.

ruleRisk-based action classificationSorts intent into categories that matter: infrastructure provisioning, data destruction, credential and secret manipulation, remote code execution, access control changes.
lock_personLeast-agency accessOverprivileged static credentials give way to task-scoped rules, enforced at the point that carries the traffic.
do_not_disturb_onInterception and kill switchesHalts destructive commands as they are issued: stopping production servers, purging databases, rewriting firewall rules.
laptop_macEnforced at the deviceManaged endpoints are configured through MDM, so the same policy reaches the machine an agent runs on, with no software to install and no second console to operate.
person_addHuman in the loopHolds a high-risk action and routes it to an approver, with the full context of the request.
policyPolicy per actionEach action is judged on its own, so a session that was safe a minute ago is checked again.
receipt_longDecision evidenceEvery allow, hold and block is written to the audit trail with the intent that produced it.
Action requestSample action, judged before it runs
Enforcing
memoryAgentInfrastructure assistant
gavelIntentData destruction
dnsTargetProduction database
keyCredentialTask-scoped, read only
policyPolicyDestructive actions need approval
blockHeld for human approval
routeIn the path
memoryAgent intends an actionProvision, write, delete, execute
gavelAgent Action ControlClassify, apply policy, decide
apartmentYour infrastructureReceives only approved actions
Platformchevron_rightControls

The controls around the agent stack.

Agents reach models, tools, web, SaaS and data that your organization already runs. These four controls govern that estate, write to the same audit trail, and carry the enforcement the AI safety module decides on.

Platformchevron_rightAI Gateway

One front door for every model and tool call.

A single control point in front of every model endpoint and MCP server your enterprise uses. Credentials stay in the gateway, each call is checked before it reaches a provider, and the same stream carries the telemetry the AI safety module reads.

keyCredential custodyModel keys live in the gateway. Agents authenticate to Denovo and never hold provider credentials.
alt_routeRoutingSend each request to an approved model and provider, based on policy.
speedRate and spend limitsSet limits per user, agent, team or application.
visibility_offRedactionRemove sensitive values from prompts before they leave your environment.
ruleAllow or denyDecide in path, before a request reaches a provider.
receipt_longEvidenceEvery request and decision is written to the audit trail.
memoryAgent fleet viewEvery agent seen in traffic, with its identity, its tools and its activity.
handymanTool access postureWhich tools an MCP server advertises, and which ones agents actually call.
visibilityShadow AI detectionAI providers appearing in traffic, covered by policy or not.
Inference requestSample request, inspected in path
Enforcing
memoryCallerSupport agent
neurologyDestinationModel provider
keyCredentialHeld by gateway
chatPromptCustomer email redacted
paymentsSpendWithin team limit
routeRouteApproved model
task_altAllow with redaction
routeIn the path
memoryAgents and AI appsSend requests with a Denovo identity
alt_routeAI GatewayCredentials, routing, limits, redaction
neurologyModel providersReceive only approved requests
Platformchevron_rightAI-native SWG

A web gateway
that reads intent.

Everyday web security for users, extended to AI traffic. Policies reason about prompts, tokens, model endpoints and tool calls alongside URLs and files.

lockTLS inspectionDecrypt and inspect web traffic with per-domain profiles.
do_not_disturb_onEgress control at SNIStop connections to unsanctioned destinations before they complete.
psychologyPrompt-aware policyTell a search query from a prompt that carries source code.
publicWeb and file protectionApply category, reputation and file rules to everyday browsing.
notificationsUser notificationExplain a block to the user, with the policy that applied.
crop_freeIsolated sessionsRun an application inside a cloud browser, with downloads, copy and paste and watermarking under policy.
Web requestSample request, inspected in path
Enforcing
personUserFinance user
languageDestinationPublic AI chat site
lockTLSInspected
codeContentPasted source code
policyPolicyCode stays internal
blockBlock and notify
routeIn the path
groupUsers and devicesBrowse the web and use SaaS
travel_exploreAI-native SWGTLS inspection, intent-aware policy, SNI control
cloudWeb and SaaSReached only through approved paths
Platformchevron_rightAgentic CASB

Every identity,
governed.

Agents are sanctioned, scoped and revoked as first-class identities, together with every app and MCP server they reach. App discovery follows from agent discovery.

radarDiscoveryFind the apps, agents and MCP servers in use, from live traffic.
verified_userSanction and scopeApprove an agent and limit what it can reach.
person_offRevokeCut off an agent or app across the organization in one step.
leaderboardRisk tiersRate each application and see what is unsanctioned but in use.
loginUser directory or SSOUsers sign in against the Denovo user directory, and Denovo federates with your identity provider where you already run SSO.
cloud_syncSaaS integrationsConnect SaaS platforms out of band and scan their posture.
domainTenant restrictionPin sign-in to your own tenant.
Identity inventorySample entries from live traffic
Live
support_agentSupport agentcheckSanctioned
codeCoding assistantlockRead-only
edit_noteNote-taking appblockUnsanctioned
extensionUnknown MCP serverperson_offRevoked
syncInventory updated from traffic
routeIn the path
groupUsers and agentsEach with a verified identity
badgeAgentic CASBSanction, scope and revoke
extensionApps and MCP serversReached only by approved identities
Platformchevron_rightAgentic DLP

Data protection
for prompts.

Prompts, embeddings, tool arguments and model responses are treated as the exfiltration channels they are. Sensitivity is inferred from the data and its destination.

forumAI-channel coverageInspect prompts, embeddings, tool arguments and responses.
fact_checkContent-aware sensitivityClassify data by what it contains, with no per-app regex tuning.
arrow_outwardDestination-aware rulesBind a rule to where data is going.
descriptionIndexed documentsRecognize fragments of your own sensitive files.
tuneOrganization-wide controlChoose whether DLP findings may block, for the whole organization.
Prompt inspectionSample tool call, inspected in path
Enforcing
inputChannelTool argument
manage_searchFoundCustomer email, contract value
arrow_outwardDestinationExternal model
lockSensitivityConfidential
visibility_offActionRedact before sending
task_altAllow with redaction
routeIn the path
descriptionPrompts, files and tool callsLeave users and agents
data_loss_preventionAgentic DLPClassifies data and checks the destination
neurologyModels and destinationsReceive only permitted data
Platformchevron_rightPlatform overview

One foundation under every module.

One identity model, one telemetry stream, one policy language and one audit trail. Every module runs on Denovo Core, and reaches the same verdict for a user and for an agent.

fingerprint

Identity

Users, agents, devices and apps resolve to one identity, with posture attached.

stream

Telemetry

Every request, prompt and tool call is recorded on the path it takes.

account_tree

Policy compilation

Policies are written once and compiled for each enforcement point.

receipt_long

Audit evidence

Each decision is kept as evidence your auditors can review.

Building Trust from Scratch

Bring your whole estate under one policy.

Denovo verifies, inspects and decides on live traffic from users, devices, workloads and agents, across the models, tools, web, SaaS and data they reach. See it running on your own stack.