SOC 2-ALIGNED  ·  EU AI ACT  ·  NIST AI RMF  ·  ISO 42001-READY [email protected]
Odingard / Cerberus Book a Demo
Cerberus  ·  Defense  ·  Open Core

Block the Lethal Trifecta at the tool boundary.

Cerberus wraps every tool executor, scores the whole session, and intercepts the call the moment privileged data, injection, and outbound intent correlate — before it fires. Self-hosted, inside your own VPC.

Cerberus mark
The problem

An AI agent with tools is an insider threat waiting to happen.

Give an agent access to your data and the open web and three things eventually line up in a single session: it reads something privileged, it ingests something untrusted, and it has a way to send data out. That combination — the Lethal Trifecta — is how prompt-injection turns into real data theft. Cerberus watches for exactly that correlation and stops the outbound call.

Detection pipeline

Four layers, one verdict.

L1

Data-source classification

Every value entering the agent is tagged by trust: privileged store, user input, tool output, or untrusted web content.

L2

Injection detection

Untrusted content is inspected for instructions that try to redirect the agent — the hijack attempt itself.

L3

Exfiltration intent

Outbound tool calls are scored for whether privileged data is about to leave to an attacker-influenced destination.

L4

Provenance & blast radius

The durable ledger traces how tainted data spreads across shared agent memory, so a single poisoned write can be quarantined precisely — clean records and the audit trail stay intact. (Enterprise)

See it live

Real agents. Real tools. Live interception.

Watch Cerberus stop data exfiltration in real time across finance, healthcare, insurance, and government scenarios — with two lines of guard().

Open the live demo →
Enterprise

Live operations. Governed evidence.

A real run, shown from two angles: the operational pulse of a real gpt-4o-mini agent passing through guard(), and the read-only evidence surfaces that explain what the engine observed and contained.

Live operational view
Grafana AI Security Monitor showing live agent actions, stopped threats, and risk scores

Grafana operational overview from a live run window.

Grafana tool-level breakdown and response summary for the live Cerberus run

Tool-level activity and response types from the same window.

Governance and evidence view
Cerberus Control Plane Prevention Ledger showing proof-backed blocked and flagged receipts

Prevention Ledger: proof-backed engine receipts.

Cerberus Control Plane Provenance and Containment view showing quarantined nodes and blast radius

Provenance and Containment: a read-only blast-radius view.

Cerberus Control Plane Posture and Oversight view showing coverage and audit evidence

Posture and Oversight: coverage and audit evidence.

The Control Plane renders engine evidence for review; enforcement remains the engine's action. Grafana figures show one live run window, not lifetime or benchmark totals.

Deploy

Open core

The detection engine, MIT-licensed. Wrap your executor with guard() or run the HTTP gateway. Works with LangChain, Vercel AI SDK, and OpenAI Agents.

npm install @cerberus-ai/core

Enterprise

Durable SQLite provenance ledger, blast-radius containment, egress/SSRF guard, policy tuning, and audit-ready evidence export. Runs entirely in your infrastructure — data never leaves your VPC. Deployed with our team.

Talk to Engineering ↗