Services
AI security
Securing the applications, agents and tool integrations built on language models.
Assume the model will be tricked.
Agents and tools get least-privilege access and isolated execution, so a successful prompt injection can only reach what that tool was allowed to.
Secure Claude Code
Rolling out Claude Code to engineering teams with managed settings, permission rules, sandboxing, MCP allowlists and audit logging, so developers keep the speed without handing an agent the keys.
Secure Codex
The same for OpenAI Codex: approval and sandbox modes set per repository, scoped credentials, network egress limits, and a review path for what the agent changes.
LangChain
Security review and hardening of LangChain applications: tool permissions, input and output handling, secrets, and tracing that captures what an agent actually did.
Firecracker
Firecracker microVM sandboxes for running untrusted or model-generated code, with resource limits and network isolation.
Kata Containers
VM-isolated pods on Kubernetes for agent workloads, using Kata runtime classes alongside normal containers.
WASM sandboxes
WebAssembly runtimes for lightweight tool execution, with capability grants limited to what each tool needs.
MCP security
Threat modeling and hardening for MCP servers and clients: authentication, scoped tool access, prompt injection through tool output, and audit logging.