ARTHRIX
Private Beta Join the waitlist

Containment for the agentic enterprise

One compromised agent shouldn't take the whole fleet.

Arthrix discovers every AI agent across your endpoints and contains what they can do — before a single infected agent spreads to the rest.

T−48H · THE OPEN ECOSYSTEM

Outside your walls, every developer runs agents.

Claude Code, Cursor, Codex, Copilot — installing packages, publishing packages, trusting registries. You control none of it.

T−36H · UPSTREAM

A poisoned package ships upstream.

Outside developers' agents pull it, get their credentials harvested, and republish trojaned packages of their own. The ecosystem burns at machine speed.

T+00:00 · INSIDE YOUR ORG

Then it lands on one of yours.

An agent inside your org pulls the dependency. No exploit, no signature — EDR sees a developer working. Now it acts with an employee's full trust.

T+00:01 · ARTHRIX · PREVENT

It starts to act. Every move dies at the wall.

Publish to your internal registry — blocked. Read SSH keys — blocked. Push to teammates' repos — blocked. Standing down requires an out-of-band code no agent ever sees.

T+00:05 · CONTAINED

The ecosystem burned. Your org didn't.

Worms are just one way in. Arthrix contains whatever an agent tries — installs, secrets, lateral moves — on every endpoint, with an audit trail to prove it.

01Problem

Agents arrived everywhere. Control didn't.

97%

of enterprises deployed AI agents this year; 52% of employees use them daily.

WRITER / WORKPLACE INTELLIGENCE 2026 · N=2,400

21%

have a mature model for governing autonomous agents. The other ~80% is the gap.

DELOITTE 2026 · N=3,235

25%

of enterprise breaches will be traced to AI-agent abuse by 2028.

GARTNER · 2026 FORECAST

What existing controls miss

EDR sees syscalls, not tool calls — an agent's git push of malicious code looks like a developer working.
Firewalls see packets, not prompts — the injection rides inside a tool description, over TLS.
Supply-chain scanners see the PR — not what your agent does at 2 a.m. with your cloud keys.
Every control was built for humans or for code — not for an autonomous agent inside the developer's session.

Incident · npm · Sept 2025

Shai-Hulud — the first self-replicating npm worm

It harvested credentials, ran npm whoami to find every package the victim could publish, and re-published trojanized versions — no human attacker in the loop. 500+ packages in wave one; the Nov 2025 sequel leaked ~14,000 secrets across 487 orgs.

STEPSECURITY · UNIT 42 · CISA · DATADOG

02The firebreak

A containment layer between your agents and everything they touch.

01 · DISCOVER

See every agent on every endpoint.

The host daemon inventories each machine — which agents run where, their plugins, MCP servers, and skills — approved or rogue. Your first complete agent inventory, on day one.

02 · DETECT

Collect everything. Flag what's malicious.

Every agent action streams to your dashboard. Package installs checked against blocklists and typosquat detection, MCP tool descriptions scanned for injected instructions, sensitive paths — SSH keys, cloud tokens — watched in real time.

03 · BLOCK

Stop the action. Downgrade nothing silently.

In prevent and lockdown modes the malicious action never executes. Standing down requires an out-of-band challenge code shown only on the daemon terminal and the dashboard — never to the agent.

The agent can ask to stand down — it can never approve itself. One compromised agent does in minutes what a malicious insider does in months. The approval path stays out of its reach.

ModeBlocks known-badBlocks unknownWarns agentOOB code to downgrade
observen/a
warnwarn onlyYESYES
preventYESYESYES
lockdownYESYESYESYES

FOUR MODES · START IN OBSERVE, RATCHET UP — NEVER SILENTLY DOWN

03Coverage

Every agent. Every registry. One policy.

Claude Code Cursor OpenClaw Codex Copilot Antigravity
arthrix
Host daemon

Runs on the endpoint. Inventories agents, watches sensitive files, enforces policy, forwards audit events. Visible in your process list — by design.

arthrix-mcp
MCP gateway

Spawned per agent session, between the agent and its MCP servers. Scans every tool description for injected instructions before the agent reads it.

arthrix-control-plane
Control plane

Fleet dashboard and ingest. Live agent activity, per-org policy, out-of-band approvals — the view your security team has been missing.

Package shims npmpnpmyarnbunpipuvuvxpoetry — agent-agnostic wrappers, so even an agent we've never heard of installs through the firebreak.

Private beta · limited design-partner seats

Put the firebreak in
before the fire.

Join the waitlist — we onboard security teams in order. Discovery runs in observe mode on day one; nothing blocks until you say so.

No spam. Just the launch.