Your agents talk to tools.
Who's listening?

Every tool call, every delegation, every agent-to-agent interaction — inspected, governed, and enforced. In real time. Before the damage is done.

Catches what rules can't

Pattern matching catches known attacks. But what about the novel ones? The social engineering disguised as a database query? The slow data exfiltration that looks like normal usage?

Clampd combines deterministic rules with semantic analysis and behavioral intelligence. Known threats are blocked instantly. Unknown threats are caught by what the agent does differently — not by what the payload looks like.

16 tool categories • Sub-10ms median latency

Your rules, your policies, your way

Clampd ships with comprehensive built-in detection. But every team has unique threats. Import your own detection rules in Sigma YAML format — the same format your SOC team already writes. Create custom keyword dictionaries. Define threat-specific patterns.

Policies are written in Cedar — AWS's open-source authorization language. Human-readable, version-controllable, hot-reloadable. No restarts, no downtime. Change a policy in the dashboard and it takes effect in seconds across your entire agent fleet.

Sigma rules • Cedar policies • Custom keywords • TOML rule packs • CSV import • Hot-reload

Agents talking to agents is the new attack surface

When Agent A delegates to Agent B, and B delegates to C — who verifies the chain? Who checks that B didn't change its capabilities after approval? Who notices when C starts behaving differently after talking to a compromised agent?

Clampd tracks every delegation, verifies every handoff, and detects when agent behavior shifts after inter-agent contact. The entire communication graph is monitored, governed, and auditable.

Delegation depth limits • Cycle detection • Rug-pull verification • Workflow boundaries

The problem nobody else is solving

A compromised agent doesn't just fail — it infects every agent it communicates with. A traditional firewall sees a perfectly valid, authenticated JSON request. Clampd sees the behavioral shift that follows.

Learns what normal looks like. Catches what isn't.

Every agent builds a behavioral profile over time. When something changes — new tools, unusual hours, unexpected data volumes, different output patterns — Clampd flags it. Even if no rule fires. Even if the payload looks clean.

The more agents you monitor, the better the detection gets. Patterns across your agent fleet reveal coordinated threats that single-agent monitoring misses entirely.

From detection to containment in milliseconds

Detection without response is just logging. When Clampd identifies a threat, the kill switch propagates across your entire fleet in under 25ms. Compromised agents are isolated. Contacts are flagged for enhanced monitoring. The blast radius is contained before it spreads.

Kill cascade • Contact quarantine • Auto-suspension • Full audit trail

Built for teams that answer to regulators

Scope-based least-privilege per agent. Delegation approval workflows with tool-level restrictions. Payment guardrails with per-agent spend limits and vendor controls. Every decision logged, every action auditable, every policy version-controlled.

HIPAA • GDPR • SOC 2 • ISO 27001

One Line to Integrate

clampd.openai(client, agent_id="my-agent") — Python and TypeScript. Works with OpenAI, Anthropic, LangChain, Google ADK, and any MCP server. No configuration required. Protection activates immediately.

See Everything

Live risk feed with real-time event streaming. Delegation graph with security signals. Agent behavioral profiles. Kill switch controls. Policy editor. Compliance reports. Everything your security team needs, in one dashboard.

Coming Next